Top

Singaporean authorities alert businesses to Bitcoin ransomware risk

Policy & Regulation·June 11, 2024, 6:07 AM

Akira ransomware, responsible for stealing $42 million from over 250 organizations across North America, Europe and Australia in just a year, is now targeting businesses in Singapore. In response, Singaporean authorities have issued a joint advisory warning local businesses about the increasing threat posed by a variant of this ransomware.

https://asset.coinness.com/en/news/2a60ac3f2278d1ab842181ec0c178bfb.webp
Photo by Mike Enerio on Unsplash

Alert follows complaints

The alert follows multiple complaints from victims, prompting agencies like the Cyber Security Agency of Singapore (CSA), the Singapore Police Force (SPF) and the Personal Data Protection Commission (PDPC) to take action. These agencies emphasize the urgency of recognizing and combating this threat.

 

How Akira operates

Akira affiliates employ various techniques to infiltrate a victim's network. These include exploiting known vulernabilities. For example, that could mean the targeting of services like Cisco virtual private networks (VPNs) that have been configured without multi-factor authentication (MFA).

 

Another approach that the ransomware incorporates is attacking external-facing services such as the Remote Desktop Protocol (RDP) via brute force. Social engineering is another tool within its repertoire. This involves tricking victims into downloading malicious software or entering credentials on phishing websites.

 

There is a marketplace for compromised credentials in the dark web. Akira also relies on such data, acquiring it from access brokers who sell network access. 

 

Once inside a network, Akira affiliates often create new domain accounts to maintain persistent access, even after reboots. They use numerous tools to steal user credentials, escalate privileges and spread throughout the network.

 

Detection and prevention measures

The Singaporean advisory outlines several strategies for detecting, deterring and neutralizing Akira attacks. Authorities strongly advise against paying ransoms, on the basis that doing so does not guarantee data recovery or prevent future attacks.

 

Authorities also warn that paying ransoms can encourage further attacks. The FBI has noted that Akira operators do not contact victims. Instead, they expect victims to initiate contact.

 

Payment in Bitcoin

The advisory outlines how Bitcoin is implicated in the ransomware scam. It states:

”Ransom payments are requested in Bitcoin, which are directed to cryptocurrency wallet addresses specified by the affiliates. The TOR site (.onion) where victims contact the affiliates, contains stolen information and a list of the affected organisations.”

 

It’s not the first time that Singaporean authorities have issued warnings that have implicated Bitcoin and crypto. In January, the CSA and SPF, in a joint advisory, suggested that people should use hardware wallets in an effort to guard against crypto-related malware and phishing attacks.

 

A number of weeks prior to that, Singapore’s former Prime Minister, Lee Hsien Loong, took to Facebook to issue a warning with regard to a crypto scam that involved the use of deceptive content generated using artificial intelligence (AI).

 

Mitigation techniques

Businesses are being urged by the authorities to adopt best practices to mitigate the Akira ransomware threat. They suggest the implementation of a recovery plan alongside the use of multi-factor authentication (MFA) in order to secure data and the access to that data. 

 

They also suggest filtering network traffic as it helps in identifying and blocking malicious activities. Meanwhile, disabling unused ports and hyperlinks curbs the risk further as it reduces the attack surface. Lastly, the authorities suggested the use of system-wide encryption to protect data even if it is accessed by unauthorized entities.

More to Read
View All
Web3 & Enterprise·

Sep 15, 2023

Galaxia Moneytree Forms Aviation Asset Tokenization Consortium

Galaxia Moneytree Forms Aviation Asset Tokenization ConsortiumKorean financial platform services provider Galaxia Moneytree announced that it has signed a memorandum of understanding (MOU) to establish a consortium for the development of a security token offering (STO) platform that issues tokenized aviation assets — the first of its kind in the country. Shinhan Securities, Eugene Investment and Securities, VMIC Aviation, and Cirium have signed on as members.Photo by John McArthur on Unsplash“This consortium will be a significant step in our endeavors to become a leading entity for innovation in the field of the tokenization of aviation assets. Our agreement will promote the advancement of the Korean aviation industry and enhance global competitiveness, providing investors with new opportunities through alternative investments,” said Shin Dong-hoon, CEO of Galaxia Moneytree.Shaping the future of aviationThe consortium aims to issue security tokens for leasing core aviation equipment such as aircraft engines, which would secure private funding and ease the burden that is imparted by leasing fees. Also, given that the most important aspect of STOs is asset valuation, the consortium has committed to issuing reliable aviation token securities to investors based on the accurate valuation of aircraft engines as determined by Cirium. Cirium is a global aviation data analytics company with 114 years of experience that provides solutions such as the valuation of aircrafts and engines, risk analytics for carbon emission reduction, and flight schedule changes.Galaxia Moneytree said that the consortium recently applied for a financial regulatory sandbox — a program introduced by the Korean government that offers special and provisional regulatory exemptions for financial services that have been recognized for their innovativeness.Partners with varying attributesGalaxia Moneytree will be responsible for overseeing the consortium as well as developing and operating the STO platform, which Shinhan Securities and Eugene Investment and Securities have agreed to provide funding for. The two securities firms will also provide management services for related trusts and accounts.Meanwhile, VMIC will take over asset management for aircraft engines and contribute various insights based on its expertise in aviation finance. VMIC Aviation is a Korean startup that specializes in innovative aircraft engine technologies by leveraging its technical and financial expertise.Discussions are also underway for cooperation with relevant government agencies such as the Ministry of Land, Infrastructure and Transport and the Korea Civil Aviation Association.The company has been working with its partner companies and communicating with government entities to tokenize a wide range of assets, from certified emissions reductions to renewable energy and horse racing. It is also taking the initiative to position itself as an industry leader by investing in joint ventures.

news
Web3 & Enterprise·

Oct 26, 2023

Web3 Fashion Platform doDRESS Opens Pop-up Store in Seoul

Web3 Fashion Platform doDRESS Opens Pop-up Store in SeouldoDRESS, a fashion and lifestyle platform created by the faculty at Kookmin University in Seoul, has opened a pop-up store in Seoul in line with the launch of its new website. doDRESS aims to create a decentralized Web3 fashion ecosystem centered around brands, creators, and influencers, providing a space to communicate with consumers and promote their businesses and content. In turn, consumers can get the chance to dive into a new form of Web3 technology and express themselves through their personal style.Photo by No Revisions on UnsplashInteractive space for creators and consumersThe pop-up store, which was revamped from an old auto repair shop, has invited some 40 designers and graphic artists to showcase and sell their unique street fashion-inspired clothing and graphic art to consumers. It will also present an opportunity for them to interact with influencers who can contribute to the marketing and distribution of their products, thus boosting their value.Creators and those who wish to become creators can upload the products they make on doDRESS. When a product is sold, every individual in the platform’s Web3 ecosystem who contributed to making it will receive a portion of the revenue.Visitors, on the other hand, can customize their own clothing by printing designs created by the artists themselves through doDRESS’s fashion stickering service, which is available both online and offline at the pop-up store. The platform also said that it would give out custom doDRESS products worth KRW 40,000 (approximately $30) on a first-come, first-served basis to 70 visitors on weekdays and 200 on weekends.Future plans for growthIn the future, doDRESS aims to expand on a global scale and add more clothing products to its services utilizing various production techniques like 3D printing.The pop-up store will be open until next Wednesday (local time) in Seongsu-dong.

news
Web3 & Enterprise·

Dec 26, 2023

Bitget works towards goal of Bitcoin ecosystem support

Bitget works towards goal of Bitcoin ecosystem supportBitget Wallet, a Web3 trading wallet offered by the Bitget Seychelles-based crypto derivatives platform, has unveiled a plan designed to bolster its support for and development within the Bitcoin ecosystem.Photo by Kanchanara on UnsplashEnhancing user experienceIn an effort to elevate user experience and expand trading options, Bitget Wallet is committing to extensive product research, development initiatives and increased investments. The company plans on offering a wide array of services tailored to the Bitcoin ecosystem.This includes robust support for BTC asset management, cross-chain swaps, on-ramping for externally owned account (EOA)-based wallets, multi-party computation (MPC) wallets, Taproot compatibility and streamlined asset transfers for both BRC-20 tokens and NFTs. In October, Bitget announced that it was taking the route of enhanced security by embarking on integrating MPC.Integrated dApp browserThe platform also provides users with insights into macro and micro market trends through Bitget Swap, enabling interaction with popular projects via its dApp browser.Bitget Wallet’s move has already garnered support from several Bitcoin ecosystem projects, with integrations on official websites such as Unisat, ALEX Lab, LifeRestart and Bitmap Explorer. The integrated dApp browser ensures convenient user access to these projects, fostering increased engagement and accessibility.Looking forward, Bitget Wallet aims to capitalize on the medium to long-term market prospects within the Bitcoin ecosystem. The company is directing its efforts towards enhancing both technological infrastructure and product features, with a specific focus on critical areas such as Lightning Network, Nostr, Taproot Assets, BRC-20 and ARC-20 inscriptions.Facilitating cross-chain transactionsAn important facet of Bitget Wallet’s approach involves supporting multiple address formats, particularly within the Lightning Network. By doing so, the platform aims to improve asset transfer efficiency and introduce asset swaps between the Bitcoin mainnet and the Lightning Network. This move is geared towards facilitating cross-chain transactions between BTC and Ethereum Virtual Machine (EVM) assets on Bitget Swap, providing users with increased opportunities for portfolio diversification.Alvin Kan, the Chief Operating Officer of Bitget Wallet, underscored the significance of Bitcoin as the foundational cornerstone of the crypto industry. He emphasized the platform’s commitment to becoming a key player in the growing Bitcoin ecosystem, providing users with robust and seamless ways to manage and grow their assets.Formerly known as BitKeep, Bitget Wallet stands as Asia’s largest all-in-one Web3 trading wallet, boasting a five-year legacy and over 12 million users worldwide. On a global basis, the non-custodial wallet recently ranked fourth overall in terms of the number of wallet downloads.Bitget acquired the Singaporean startup wallet project in June. Its addition helped the broader Bitget platform to achieve the milestone of 20 million users. The product was rebranded as Bitget Wallet shortly afterwards.The company is keen to support other blockchain networks and ecosystems also. Earlier this month, the company announced an investment into Morph, a layer-2 blockchain that uses zero knowledge roll-up technology in an effort to focus on enhanced consumer experience.Last week, the platform added support for ZKFair, a zero knowledge layer-2 network which is based on the Polygon CDK.

news
Loading