Top

Singaporean authorities alert businesses to Bitcoin ransomware risk

Policy & Regulation·June 11, 2024, 6:07 AM

Akira ransomware, responsible for stealing $42 million from over 250 organizations across North America, Europe and Australia in just a year, is now targeting businesses in Singapore. In response, Singaporean authorities have issued a joint advisory warning local businesses about the increasing threat posed by a variant of this ransomware.

https://asset.coinness.com/en/news/2a60ac3f2278d1ab842181ec0c178bfb.webp
Photo by Mike Enerio on Unsplash

Alert follows complaints

The alert follows multiple complaints from victims, prompting agencies like the Cyber Security Agency of Singapore (CSA), the Singapore Police Force (SPF) and the Personal Data Protection Commission (PDPC) to take action. These agencies emphasize the urgency of recognizing and combating this threat.

 

How Akira operates

Akira affiliates employ various techniques to infiltrate a victim's network. These include exploiting known vulernabilities. For example, that could mean the targeting of services like Cisco virtual private networks (VPNs) that have been configured without multi-factor authentication (MFA).

 

Another approach that the ransomware incorporates is attacking external-facing services such as the Remote Desktop Protocol (RDP) via brute force. Social engineering is another tool within its repertoire. This involves tricking victims into downloading malicious software or entering credentials on phishing websites.

 

There is a marketplace for compromised credentials in the dark web. Akira also relies on such data, acquiring it from access brokers who sell network access. 

 

Once inside a network, Akira affiliates often create new domain accounts to maintain persistent access, even after reboots. They use numerous tools to steal user credentials, escalate privileges and spread throughout the network.

 

Detection and prevention measures

The Singaporean advisory outlines several strategies for detecting, deterring and neutralizing Akira attacks. Authorities strongly advise against paying ransoms, on the basis that doing so does not guarantee data recovery or prevent future attacks.

 

Authorities also warn that paying ransoms can encourage further attacks. The FBI has noted that Akira operators do not contact victims. Instead, they expect victims to initiate contact.

 

Payment in Bitcoin

The advisory outlines how Bitcoin is implicated in the ransomware scam. It states:

”Ransom payments are requested in Bitcoin, which are directed to cryptocurrency wallet addresses specified by the affiliates. The TOR site (.onion) where victims contact the affiliates, contains stolen information and a list of the affected organisations.”

 

It’s not the first time that Singaporean authorities have issued warnings that have implicated Bitcoin and crypto. In January, the CSA and SPF, in a joint advisory, suggested that people should use hardware wallets in an effort to guard against crypto-related malware and phishing attacks.

 

A number of weeks prior to that, Singapore’s former Prime Minister, Lee Hsien Loong, took to Facebook to issue a warning with regard to a crypto scam that involved the use of deceptive content generated using artificial intelligence (AI).

 

Mitigation techniques

Businesses are being urged by the authorities to adopt best practices to mitigate the Akira ransomware threat. They suggest the implementation of a recovery plan alongside the use of multi-factor authentication (MFA) in order to secure data and the access to that data. 

 

They also suggest filtering network traffic as it helps in identifying and blocking malicious activities. Meanwhile, disabling unused ports and hyperlinks curbs the risk further as it reduces the attack surface. Lastly, the authorities suggested the use of system-wide encryption to protect data even if it is accessed by unauthorized entities.

More to Read
View All
Web3 & Enterprise·

Jun 09, 2023

Animoca Brands Expands Focus to Non-US Markets

Animoca Brands Expands Focus to Non-US MarketsHong Kong-based Web3 and blockchain unicorn, Animoca Brands, is shifting its attention to markets outside the United States following the Securities and Exchange Commission’s (SEC) classification of its $SAND token as an unregistered security.This move comes after the SEC named $SAND, along with other tokens like Solana and Polygon, in lawsuits against major exchanges Binance and Coinbase Global. The labeling of these tokens as securities by the SEC poses legal risks for companies involved in their sale.Photo by Zulian Firmansyah on UnsplashNavigating regulatory challengesAnimoca Brands, led by Co-Founder and Chairman Yat Siu, has long embraced a global approach rather than focusing solely on one territory. Siu clarified the firm’s response to the latest regulatory development to the South China Morning Post (SCMP) via email on Thursday.He emphasized that while the SEC concentrates on the US, Animoca Brands operates in more progressive jurisdictions such as Hong Kong and Japan, where $SAND is widely available and accepted. In response to the recent blockchain-hostile climate in the US, the company has proactively started emphasizing other markets, reducing its reliance on the US market and mitigating potential risks associated with regulatory actions.Exchange business impactWhile Coinbase CEO Brian Armstrong has declared that his company has no intentions of delisting tokens labeled as securities by the SEC, this decision poses challenges for other exchanges less committed to selling these tokens. Dan Gallagher, Chief Legal Compliance and Corporate Affairs Officer of Robinhood Markets, expressed concerns about listing tokens due to regulatory rules and the uncertainty surrounding tokens created by organizations outside the US.These developments could have a chilling effect on exchanges, prompting crypto firms to consider moving away from the US market due to perceived uncertainty and the associated legal risks. As a demonstration of that, in a bankruptcy court hearing on Thursday, it emerged that the FTX Debtor is talking with bidders with a view to restarting the international business but restarting the US-based business is less certain.Animoca’s Middle East ventureIn a further display of its commitment to expanding outside the US, Animoca Brands announced plans in March to make significant investments, worth tens of millions of dollars, in the Middle East. This move reflects the company’s proactive strategy to tap into non-US markets and leverage the growth potential offered by progressive jurisdictions.Animoca Brands’ decision to prioritize non-US markets and reduce its reliance on the US market aligns with its global operating approach. The SEC’s classification of $SAND as a security has prompted the company to shift its attention to more progressive jurisdictions where $SAND remains widely accessible.As other firms, including Ripple, also explore growth opportunities outside the US, the global landscape of the crypto industry is evolving. By navigating regulatory challenges and expanding into promising markets, Animoca Brands aims to position itself for continued success and mitigate potential risks associated with the SEC’s actions in the US market.

news
Web3 & Enterprise·

Jan 21, 2025

Jio launches JioCoin reward token

Indian multinational technology firm Jio Platforms, a subsidiary of India’s largest private sector company, Reliance Industries, has launched JioCoin, a rewards-based token, on the Polygon blockchain. While Jio Platforms has yet to make an official announcement related to JioCoin, Kashif Raza, the founder of Indian crypto education startup Bitinning, took to the X social media platform on Jan. 16 to highlight his discovery that JioCoin had been launched and that the tokens could be accumulated via the JioCoin Wallet, a Web3 wallet. Polygon Labs partnershipLast week, it emerged that Jio Platforms had entered into a partnership with Polygon blockchain developer Polygon Labs. Polygon co-founder Sandeep Nailwal told Cointelegraph that Polygon Labs intends to support Jio to enable blockchain integration across a spectrum of Jio applications. In a follow-up post, Raza provided a more detailed account of the offering. The crypto educator explained that the token “is a mechanism to reward internet users for surfing the internet on the JioSphere browser.”Photo by GuerrillaBuzz on UnsplashUse case speculationOn that basis, it’s likely that the emergence of JioCoin is the first demonstration of one of the outcomes of that collaboration.  In the absence of an official announcement and a specific clarification of the intended use case for JioCoin, Raza speculated that its likely use case will be to act as a currency within the Jio network. He explained that within Jio’s sphere, thousands of companies are interacting with each other. Raza speculated that in the future, users would be able to use JioCoin to pay for gas at gas stations or renew mobile phone services. Jio’s parent company operates a network of gas stations in partnership with BP. He believes that JioCoin could potentially give Jio an edge in competing with other internet browser providers like Google, Brave and Microsoft, while suggesting that Reliance Industries group companies could run one of the most significant rewards programs in the world via JioCoin. Polygon adoptionIndian venture capitalist and blockchain enthusiast Aditya Singh suggested that the move will help Polygon from an awareness and adoption perspective. However, he outlined that while this is a big deal, it’s not the first time that Polygon has struck big-name partnerships, having done so in the past with Meta, Disney, Nike, Adidas, Adobe, Reddit and others. Raza believes the partnership provides significant validation for Polygon, given Jio's reputation. He suggested that, as a consequence, other large Indian corporations may choose to launch an ecosystem coin on the Polygon blockchain. If JioCoin fulfills its potential and turns out to be a success, the Polygon network will see a significant rise in the overall number of transactions processed. In a similar vein, Jio could bring a substantial user base to Polygon.  While Singh and Raza see JioCoin as a largely positive development, its introduction hasn’t occurred without criticism. Author and crypto analyst Sunil Aggarwal took to social media to warn the community to investigate the token further before automatically assuming it to be a huge milestone for Polygon and crypto generally. He cited concerns related to the transparency and integrity of the token offering.

news
Web3 & Enterprise·

Oct 23, 2023

Korea’s ABB Joins Hands with Vietnam’s DTS Group for Web3 Development

Korea’s ABB Joins Hands with Vietnam’s DTS Group for Web3 DevelopmentSouth Korean Web3 consulting firm ABB announced Monday that it has signed a comprehensive memorandum of understanding (MOU) with DTS Group, one of the fastest-growing companies in Vietnam.The agreement was signed at the 20th World Web 3.0 NFT META Marvels Bangkok 2023 conference held in the Thai capital last Friday, with ABB’s CEO, Jung Joo-pil, and DTS Group’s Chairman, Truong Gia Bao, in attendance.Photo by Shubham Dhage on UnsplashFostering Web3 innovation and diplomatic tiesThis collaboration is expected to contribute significantly to the development of Web3 in both Korea and Vietnam. They will start by discovering and investing in promising blockchain startups and expand into more diverse business areas, then further enhance their cooperation in Web3 technology development and promotional marketing in the future.About ABB and DTS GroupABB is primarily engaged in consulting, promotional marketing, and fundraising for blockchain-related projects. It is widely known as the publisher of the Korean blockchain monthly magazine Blockchain Today, through which it contributes to the growth of the Korean blockchain industry.DTS Group, on the other hand, is one of the fastest-growing firms in Vietnam and operates via four main subsidiaries, including DTS Foundation, which focuses on the incubation of blockchain startups; DTS Ventures, a venture capital firm that invests in blockchain startups; DTS Media, which engages in marketing and event organization; and Mira Blockchain Center, which focuses on the development and support of blockchain and AI technologies.

news
Loading