Top

Singaporean authorities alert businesses to Bitcoin ransomware risk

Policy & Regulation·June 11, 2024, 6:07 AM

Akira ransomware, responsible for stealing $42 million from over 250 organizations across North America, Europe and Australia in just a year, is now targeting businesses in Singapore. In response, Singaporean authorities have issued a joint advisory warning local businesses about the increasing threat posed by a variant of this ransomware.

https://asset.coinness.com/en/news/2a60ac3f2278d1ab842181ec0c178bfb.webp
Photo by Mike Enerio on Unsplash

Alert follows complaints

The alert follows multiple complaints from victims, prompting agencies like the Cyber Security Agency of Singapore (CSA), the Singapore Police Force (SPF) and the Personal Data Protection Commission (PDPC) to take action. These agencies emphasize the urgency of recognizing and combating this threat.

 

How Akira operates

Akira affiliates employ various techniques to infiltrate a victim's network. These include exploiting known vulernabilities. For example, that could mean the targeting of services like Cisco virtual private networks (VPNs) that have been configured without multi-factor authentication (MFA).

 

Another approach that the ransomware incorporates is attacking external-facing services such as the Remote Desktop Protocol (RDP) via brute force. Social engineering is another tool within its repertoire. This involves tricking victims into downloading malicious software or entering credentials on phishing websites.

 

There is a marketplace for compromised credentials in the dark web. Akira also relies on such data, acquiring it from access brokers who sell network access. 

 

Once inside a network, Akira affiliates often create new domain accounts to maintain persistent access, even after reboots. They use numerous tools to steal user credentials, escalate privileges and spread throughout the network.

 

Detection and prevention measures

The Singaporean advisory outlines several strategies for detecting, deterring and neutralizing Akira attacks. Authorities strongly advise against paying ransoms, on the basis that doing so does not guarantee data recovery or prevent future attacks.

 

Authorities also warn that paying ransoms can encourage further attacks. The FBI has noted that Akira operators do not contact victims. Instead, they expect victims to initiate contact.

 

Payment in Bitcoin

The advisory outlines how Bitcoin is implicated in the ransomware scam. It states:

”Ransom payments are requested in Bitcoin, which are directed to cryptocurrency wallet addresses specified by the affiliates. The TOR site (.onion) where victims contact the affiliates, contains stolen information and a list of the affected organisations.”

 

It’s not the first time that Singaporean authorities have issued warnings that have implicated Bitcoin and crypto. In January, the CSA and SPF, in a joint advisory, suggested that people should use hardware wallets in an effort to guard against crypto-related malware and phishing attacks.

 

A number of weeks prior to that, Singapore’s former Prime Minister, Lee Hsien Loong, took to Facebook to issue a warning with regard to a crypto scam that involved the use of deceptive content generated using artificial intelligence (AI).

 

Mitigation techniques

Businesses are being urged by the authorities to adopt best practices to mitigate the Akira ransomware threat. They suggest the implementation of a recovery plan alongside the use of multi-factor authentication (MFA) in order to secure data and the access to that data. 

 

They also suggest filtering network traffic as it helps in identifying and blocking malicious activities. Meanwhile, disabling unused ports and hyperlinks curbs the risk further as it reduces the attack surface. Lastly, the authorities suggested the use of system-wide encryption to protect data even if it is accessed by unauthorized entities.

More to Read
View All
Policy & Regulation·

Apr 26, 2023

Terraform Labs Co-Founder Indicted in South Korea

Terraform Labs Co-Founder Indicted in South KoreaTen individuals linked to the Terra USD collapse have been indicted in South Korea on charges associated with violations of capital markets law, including the Co-Founder of Terraform Labs, Daniel Shin. That’s according to a report published by Bloomberg on Tuesday.©Pexels/Donald TongTwo of the ten were charged with breach of trust while the remaining eight, including Shin, were charged with illegal trading. Prosecutors confirmed that all of the charged individuals have ties to Terraform Labs, the company responsible for developing the Terra protocol, and the Terra USD (TUSD) stablecoin and Luna cryptocurrency which collapsed in 2022.It’s understood that the ten individuals were also accused of illegal disclosure of clients’ payment information and the embezzlement of corporate funds. The authorities have claimed that the ten individuals are responsible for causing “astronomical damage” to investors. They estimate that all ten of them took 463 billion won, around $347 million, in profit.Business interestsShin co-founded Terraform Labs with Do Kwon in 2018. He left the project in 2020, long before its spectacular failure in 2022. However, he would have profited considerably from the project. Prior to co-founding Terraform Labs, Shin had founded lifestyle commerce company TMON in 2010. Two years later, he founded venture capital and private equity firm, Fast Track Asia while in 2017 he was a founding partner of another venture capital and private equity firm, Bass Investment.He remains involved in all of those other businesses. Furthermore, Shin founded integrated payments firm PortOne Global in January 2020, immediately upon exiting Terraform Labs. He remains CEO of PortOne Global today.$185 million frozenOn Tuesday, the Seoul Southern District Prosecutor’s Office outlined that it had frozen assets to the value of 246.8 billion won, approximately $185 million, belonging to those that it has brought charges against. South Korean authorities had previously acknowledged a difficulty in seizing assets related to Terraform Labs Co-Founder Do Kwon. It’s understood that a transfer of funds from Do Kwon to a prominent South Korean law firm is being investigated. Otherwise, the search for funds has led them overseas where it’s understood that Do Kwon purchased real estate in his mother’s name in the United States in a bid to evade asset confiscation.Free pending trialShin remains at liberty pending trial. Back in December, a South Korean court turned down a request to arrest him on the basis that he wasn’t likely to destroy evidence and wouldn’t pose a flight risk.That hasn’t proven to be the case where his former colleague Do Kwon is concerned. Do Kwon fled to Montenegro where he was recently charged with having entered the country on false documents. Both South Korea and the United States have formally applied for his extradition. In the United States, the Securities and Exchange Commission (SEC) has sued both Do Kwon and Terraform Labs. Terraform Labs subsequently submitted a request to the courts in the US to dismiss the lawsuit, claiming the SEC lacks jurisdiction.

news
Policy & Regulation·

Apr 11, 2023

North Korea Using DeFi for Money Laundering

North Korea Using DeFi for Money LaunderingThe United States Treasury issued a warning on Thursday where it identifies North Korea as a user of DeFi services for money laundering. According to the Treasury, both North Korea and criminal organizations have been using DeFi platforms to launder dirty money.©Pexels/PixabayWhile DeFi has been praised for its potential to democratize finance and provide greater financial freedom to users, it has also been criticized for its lack of regulatory oversight. According to the Treasury, this lack of oversight has made DeFi platforms an attractive target for money launderers and other criminal organizations.In its warning, the Treasury noted that North Korea has been using DeFi platforms to launder money and evade international sanctions. The country is believed to have developed a sophisticated system for laundering money through cryptocurrency exchanges, and it is now turning its attention to DeFi platforms.Illicit money movementCriminal organizations are also using DeFi services for money laundering, according to the Treasury. These groups are said to be using DeFi platforms to move money around the world, in order to avoid detection and to launder the proceeds of their illicit activities.The use of DeFi for money laundering poses a significant challenge for law enforcement agencies, as these platforms operate outside of the traditional banking system and are often difficult to track. The Treasury has urged DeFi platforms to implement strong anti-money laundering (AML) and know-your-customer (KYC) policies, in order to prevent their services from being used for criminal activities.The warning from the Treasury comes at a time when DeFi is becoming increasingly popular among investors and users. According to data from DeFi Pulse, the total value locked in DeFi protocols recently surpassed $100 billion, indicating a significant level of interest and investment in the sector.Calls for greater regulationHowever, the lack of regulatory oversight and the potential for DeFi to be used for money laundering and other criminal activities have raised concerns among regulators and policymakers. Some have called for greater regulation of the sector, in order to prevent its abuse by criminal organizations.Despite these concerns, many proponents of DeFi argue that the sector has the potential to transform the financial industry and provide greater financial freedom to users. They point to the benefits of decentralized systems, such as greater transparency, lower fees, and faster transaction times.The use of DeFi for money laundering is a complex issue that requires a multifaceted approach. While regulators and policymakers must work to implement strong AML and KYC policies, users and investors must also take responsibility for ensuring that they are using DeFi platforms in a responsible and legal manner.Ultimately, the future of DeFi will depend on how the sector is able to balance innovation and regulation. While DeFi has the potential to transform the financial industry, it must also be subject to appropriate oversight and accountability in order to prevent its abuse by criminal organizations.By working together, regulators, policymakers, and industry stakeholders can help to ensure that DeFi is used for its intended purpose — to provide greater financial freedom and empowerment to users around the world.

news
Web3 & Enterprise·

Nov 23, 2023

Bunzz expands Web3 enterprise services in Japan

Bunzz expands Web3 enterprise services in JapanSingapore-based company Bunzz, one of the largest dApp development platforms in the Asian region, has expanded its enterprise service offering to include the introduction of a specialized hackathon service geared towards developers in Japan.Photo by Jezael Melgoza on UnsplashWeb3 hackathon serviceThe new service offering, disclosed by the Singaporean startup via a press release published on Tuesday, follows on from a successful seed funding round that injected $4.5 million into the company. Bunzz is introducing a specialized hackathon service exclusively tailored for developers in Japan.The new service from Bunzz is designed to provide comprehensive support to projects and companies in planning and hosting hackathons, with a keen focus on meeting the unique needs of the Japanese developer community.Bunzz offers a suite of services that includes assistance in creating hackathon concepts, formulating effective marketing strategies for Japanese developers and providing extensive support throughout the entire hackathon process — from logistical arrangements to technical guidance and judging assistance. The hackathon-related service offering includes hackathon planning and design, marketing and promotion and management support.Capitalizing on Japanese Web3 growthThis expansion is not just an arbitrary move. The dApp development platform has taken note of Japan’s strong inclination towards embracing Web3 services. With that, it’s looking to capitalize on that market development.With Japan known for its openness to adopting new technologies, Japanese firms are actively seeking opportunities to integrate Web3 solutions into various facets of their operations. Back in April, the Japanese authorities published a whitepaper on Web3 titled “Web3 for All: The Future of the Digital Economy in Japan.” The objective of that whitepaper was to formulate a roadmap that could lead to the fostering of innovation when it comes to Web3.In September, Japan took a step towards allowing startups to raise capital from venture capital firms using digital assets instead of equity. The nation’s robust interest in decentralized applications and technologies has set the stage for Bunzz’s innovative offering. Added to that, Kenta Akutsu, Bunzz’ Co-Founder and CEO, is Japanese, and that may also have played into the decision to target the Japanese market in this instance.‘Bunzz for Enterprise’Earlier this month, Bunzz launched “Bunzz for Enterprise.” As part of that initiative, Bunzz offers consulting and system development support to companies attempting to enter the Web3 domain. The firm claims to have at its disposal over two hundred smart contract templates, made available to platform users via its Smart Contract Hub.In June, the fledgling Web3 platform launched a developer tool called DeCipher in an effort to assist developers in their approach to smart contract documentation, making that process more streamlined and efficient.Through this latest service offering, Bunzz is attempting to extend a warm invitation to projects and companies eager to tap into the skills and potential of Japanese developers through hackathons. This initiative presents an excellent opportunity for engagement with a community that purports to be deeply invested in Web3 and enthusiastic about exploring new technological frontiers.

news
Loading