Top

Singaporean authorities alert businesses to Bitcoin ransomware risk

Policy & Regulation·June 11, 2024, 6:07 AM

Akira ransomware, responsible for stealing $42 million from over 250 organizations across North America, Europe and Australia in just a year, is now targeting businesses in Singapore. In response, Singaporean authorities have issued a joint advisory warning local businesses about the increasing threat posed by a variant of this ransomware.

https://asset.coinness.com/en/news/2a60ac3f2278d1ab842181ec0c178bfb.webp
Photo by Mike Enerio on Unsplash

Alert follows complaints

The alert follows multiple complaints from victims, prompting agencies like the Cyber Security Agency of Singapore (CSA), the Singapore Police Force (SPF) and the Personal Data Protection Commission (PDPC) to take action. These agencies emphasize the urgency of recognizing and combating this threat.

 

How Akira operates

Akira affiliates employ various techniques to infiltrate a victim's network. These include exploiting known vulernabilities. For example, that could mean the targeting of services like Cisco virtual private networks (VPNs) that have been configured without multi-factor authentication (MFA).

 

Another approach that the ransomware incorporates is attacking external-facing services such as the Remote Desktop Protocol (RDP) via brute force. Social engineering is another tool within its repertoire. This involves tricking victims into downloading malicious software or entering credentials on phishing websites.

 

There is a marketplace for compromised credentials in the dark web. Akira also relies on such data, acquiring it from access brokers who sell network access. 

 

Once inside a network, Akira affiliates often create new domain accounts to maintain persistent access, even after reboots. They use numerous tools to steal user credentials, escalate privileges and spread throughout the network.

 

Detection and prevention measures

The Singaporean advisory outlines several strategies for detecting, deterring and neutralizing Akira attacks. Authorities strongly advise against paying ransoms, on the basis that doing so does not guarantee data recovery or prevent future attacks.

 

Authorities also warn that paying ransoms can encourage further attacks. The FBI has noted that Akira operators do not contact victims. Instead, they expect victims to initiate contact.

 

Payment in Bitcoin

The advisory outlines how Bitcoin is implicated in the ransomware scam. It states:

”Ransom payments are requested in Bitcoin, which are directed to cryptocurrency wallet addresses specified by the affiliates. The TOR site (.onion) where victims contact the affiliates, contains stolen information and a list of the affected organisations.”

 

It’s not the first time that Singaporean authorities have issued warnings that have implicated Bitcoin and crypto. In January, the CSA and SPF, in a joint advisory, suggested that people should use hardware wallets in an effort to guard against crypto-related malware and phishing attacks.

 

A number of weeks prior to that, Singapore’s former Prime Minister, Lee Hsien Loong, took to Facebook to issue a warning with regard to a crypto scam that involved the use of deceptive content generated using artificial intelligence (AI).

 

Mitigation techniques

Businesses are being urged by the authorities to adopt best practices to mitigate the Akira ransomware threat. They suggest the implementation of a recovery plan alongside the use of multi-factor authentication (MFA) in order to secure data and the access to that data. 

 

They also suggest filtering network traffic as it helps in identifying and blocking malicious activities. Meanwhile, disabling unused ports and hyperlinks curbs the risk further as it reduces the attack surface. Lastly, the authorities suggested the use of system-wide encryption to protect data even if it is accessed by unauthorized entities.

More to Read
View All
Web3 & Enterprise·

Jun 19, 2023

Korean Investment Firm Partners with Open Asset to Build Security Token System

Korean Investment Firm Partners with Open Asset to Build Security Token SystemKorea Investment and Securities (KITC), one of the major securities firms in the nation, announced today that it signed a memorandum of understanding (MOU) last week with Seoul-based blockchain developer Open Asset to construct a distributed ledger system for a security token alliance led by KITC. That’s according to a report by local news outlet Dailian.Photo by Growtika on UnsplashSecurity token groupIn March, KITC initiated a security token group called “Korea Investment ST Friends” in collaboration with online banks Kakao Bank and Toss Bank, as well as Kakao Enterprise, an artificial intelligence (AI) solution provider. The primary objective of this alliance is to establish the necessary infrastructure for issuing products suitable for security tokens.Tech expertiseOpen Asset, led by its CEO Kim Kyung-up, boasts a team of tech talents. The company played a key role in the Bank of Korea’s central bank digital currency (CBDC) project and participated in the development of Kakao-backed initiatives such as the blockchain platform Klaytn and the digital wallet Klip.Future system integrationThe partnership with Open Asset aims to integrate the forthcoming distributed ledger system into KITC’s existing securities trading platform, creating synergies for its business. Additionally, the two entities are exploring the possibility of connecting the new platform with the systems of other participants in the group in the future.Choi Seo-ryong, the head of the platform division at KITC, emphasized the investment firm’s objective of establishing market standards for security tokens that offer numerous possibilities. He added that KITC will work with Open Asset to develop an innovative and efficient system.

news
Policy & Regulation·

Aug 24, 2023

China Unveils Blockchain-Powered Data Exchange

China Unveils Blockchain-Powered Data ExchangeChinese government officials have announced the launch of a data exchange leveraging blockchain technology during the 2023 Hangzhou Summit in China on Wednesday.According to local media reports, the Hangzhou Data Exchange, introduced at the summit held in Hangzhou, aims to facilitate seamless buying and selling of Web3 data across enterprises. The event garnered participation from over 300 companies, including tech giants Alibaba Cloud and Huawei, marking a significant step towards embracing decentralized technology for data management.Photo by Xiaolin Zhang on UnsplashEnabling Web3 data tradingIt’s understood that the Hangzhou Data Exchange has been established with the aspiration of revolutionizing the trading landscape for enterprise information technology data by harnessing the capabilities of distributed ledger technology. Officials emphasize that the platform’s implementation will ensure that transactions conducted through the exchange remain unalterable and traceable.Chen Chun, the Director of the National Laboratory of Blockchain and Data Security, provided insights into the exchange’s advanced features, stating that it integrates research blockchain, privacy computing, and other cutting-edge technologies to establish a secure and confidential environment for sharing and utilizing data across departments and regions.Hangzhou’s digital economy sector has demonstrated significant growth, surpassing 500 billion Chinese yuan (equivalent to $69 billion) in 2022. This accounted for nearly 27% of the city’s total GDP. It suggests that the city is putting a strategic focus on technological development and innovation.Complex blockchain strategyChina’s stance on blockchain technology has been complex. While the Chinese authorities have been rigorous in regulating private blockchain enterprises, they have simultaneously championed government-led blockchain initiatives.President Xi Jinping, during the inauguration of the 2023 Shanghai Cooperation Organization Conference (SCO), highlighted the significance of central bank digital currencies (CBDC) in expanding the use of local currencies for settlements among SCO member countries. In a move to stimulate domestic spending, the Chinese government recently distributed over 100 million yuan worth of digital yuan CBDC to its residents.China’s promotion of its digital yuan has been unrivaled. Over the course of recent months, various initiatives have been launched to further the use of the CBDC. These initiatives have included paying state employees with the currency in Changshu, integration of the currency into the education system in Jiangsu province, and the installation of digital yuan ATMs in Hainan, among many other such projects.Likewise, when it comes to metaverse development, a series of initiatives have been established recently. Henan province established a metaverse fund in May to support metaverse-related projects. In the same month, a National Blockchain Center was established to develop talent within the sector. Around the same time frame, the city of Zhengzhou announced proposals geared towards supporting the growth and development of metaverse companies.The unveiling of the Hangzhou Data Exchange underscores China’s ongoing determination to harness blockchain’s potential, in this case relative to enhancing data trading and management within the Web3 ecosystem.

news
Policy & Regulation·

May 03, 2023

Dubai Regulator Issues Reprimand to OPNX Founders

Dubai Regulator Issues Reprimand to OPNX FoundersThe Virtual Assets Regulatory Authority (VARA), the regulator that concerns itself with the digital assets market in the Emirate of Dubai, has formally reprimanded the founders of digital asset exchange OPNX.Photo by Kai Pilger on UnsplashVARA issued an investor and marketplace alert on April 12 to inform investors that OPNX was not a licensed entity regulated by VARA and with that, it urged investors to be cautious. The regulator has now gone one further, this time formally writing to OPNX’s founders to reprimand them.The statement cites the following rationale for the issuance of the reprimand:”Carrying out VA (Virtual Asset) Exchange Services on an unregulated basis in and from the Emirate of Dubai; and Marketing, promoting and/or advertising OPNX services and its native token [FLEX] without the necessary permits from VARA.”Contextual backgroundThe statement goes on to provide the context for the regulator’s most recent action. VARA became aware of OPNX soliciting the public to use the exchange in February of this year. It noted that the business was actively marketing through various social media channels “without establishing warranted restrictions for residents of Dubai/UAE.” VARA went on to explain that OPNX commenced trading in April without having secured a regulatory license despite the activity warranting such a license.Cease and desistOn February 27, VARA issued OPNX with a cease and desist order, relative to the foundation of the business and the marketing and promotion of services. Thereafter, the exchange applied certain restrictions but the regulator deemed the measures to not have been applied comprehensively across all OPNX communication channels, prompting it to issue a further cease and desist order the following month.The investor and marketplace alert followed in April as OPNX proceeded to launch its exchange. The written reprimand was then issued on April 18, “to address historical and ongoing activity conducted on an unregulated basis.” The recipients included the OPNX founders, (Mark Lamb, Sudhu Arumugam, Kyle Davies and Su Zhu) and the firm’s CEO Leslie Lamb.Given what the regulator deems to have been “a continued lack of satisfactory remedial action [taken] by the responsible parties,” it is continuing to actively monitor the situation. VARA stated that it will further investigate OPNX’s activity to assess further corrective measures that may be required to protect the market.Lack of industry supportThe digital assets industry is in no way enamored with founders Davies and Zhu. Their record has been badly blemished by the unceremonious collapse of their crypto hedge fund, Three Arrows Capital, in 2022. That failure wreaked major damage on the overarching crypto space, directly leading to the failure of other crypto businesses later that year.Prominent crypto venture capitalist Michael Arrington said of their capital raise for OPNX that it was “the saddest bulls**t I’ve heard in a long time.” It later transpired that two of the investment firms that OPNX suggested were backing the start-up refuted the claim.In response to this latest development, OPNX’s CEO Leslie Lamb told Blockworks that the business was initially launched in Hong Kong. “To confirm, we have no Dubai or UAE customers and do full KYC on all users,” she stated.

news
Loading