Top

Singaporean authorities alert businesses to Bitcoin ransomware risk

Policy & Regulation·June 11, 2024, 6:07 AM

Akira ransomware, responsible for stealing $42 million from over 250 organizations across North America, Europe and Australia in just a year, is now targeting businesses in Singapore. In response, Singaporean authorities have issued a joint advisory warning local businesses about the increasing threat posed by a variant of this ransomware.

https://asset.coinness.com/en/news/2a60ac3f2278d1ab842181ec0c178bfb.webp
Photo by Mike Enerio on Unsplash

Alert follows complaints

The alert follows multiple complaints from victims, prompting agencies like the Cyber Security Agency of Singapore (CSA), the Singapore Police Force (SPF) and the Personal Data Protection Commission (PDPC) to take action. These agencies emphasize the urgency of recognizing and combating this threat.

 

How Akira operates

Akira affiliates employ various techniques to infiltrate a victim's network. These include exploiting known vulernabilities. For example, that could mean the targeting of services like Cisco virtual private networks (VPNs) that have been configured without multi-factor authentication (MFA).

 

Another approach that the ransomware incorporates is attacking external-facing services such as the Remote Desktop Protocol (RDP) via brute force. Social engineering is another tool within its repertoire. This involves tricking victims into downloading malicious software or entering credentials on phishing websites.

 

There is a marketplace for compromised credentials in the dark web. Akira also relies on such data, acquiring it from access brokers who sell network access. 

 

Once inside a network, Akira affiliates often create new domain accounts to maintain persistent access, even after reboots. They use numerous tools to steal user credentials, escalate privileges and spread throughout the network.

 

Detection and prevention measures

The Singaporean advisory outlines several strategies for detecting, deterring and neutralizing Akira attacks. Authorities strongly advise against paying ransoms, on the basis that doing so does not guarantee data recovery or prevent future attacks.

 

Authorities also warn that paying ransoms can encourage further attacks. The FBI has noted that Akira operators do not contact victims. Instead, they expect victims to initiate contact.

 

Payment in Bitcoin

The advisory outlines how Bitcoin is implicated in the ransomware scam. It states:

”Ransom payments are requested in Bitcoin, which are directed to cryptocurrency wallet addresses specified by the affiliates. The TOR site (.onion) where victims contact the affiliates, contains stolen information and a list of the affected organisations.”

 

It’s not the first time that Singaporean authorities have issued warnings that have implicated Bitcoin and crypto. In January, the CSA and SPF, in a joint advisory, suggested that people should use hardware wallets in an effort to guard against crypto-related malware and phishing attacks.

 

A number of weeks prior to that, Singapore’s former Prime Minister, Lee Hsien Loong, took to Facebook to issue a warning with regard to a crypto scam that involved the use of deceptive content generated using artificial intelligence (AI).

 

Mitigation techniques

Businesses are being urged by the authorities to adopt best practices to mitigate the Akira ransomware threat. They suggest the implementation of a recovery plan alongside the use of multi-factor authentication (MFA) in order to secure data and the access to that data. 

 

They also suggest filtering network traffic as it helps in identifying and blocking malicious activities. Meanwhile, disabling unused ports and hyperlinks curbs the risk further as it reduces the attack surface. Lastly, the authorities suggested the use of system-wide encryption to protect data even if it is accessed by unauthorized entities.

More to Read
View All
Web3 & Enterprise·

Nov 29, 2023

eToro, M2 secure licenses bolstering UAE crypto development

eToro, M2 secure licenses bolstering UAE crypto developmenteToro, the retail and social trading platform, has successfully secured a coveted license from the Abu Dhabi Global Market (ADGM) in the United Arab Emirates (UAE). Additionally, virtual asset firm M2 has become a fully regulated Multilateral Trading Facility (MTF) and custodian through the ADGM.Photo by Mitul Grover on UnsplasheToro global expansionIn eToro’s case, the Financial Services Permission (FSP) license empowers it to operate as a broker in securities, derivatives and crypto assets within the UAE. The firm announced its regulatory success on Monday, the first day of Abu Dhabi Finance Week.eToro’s foray into the UAE market is part of its broader global expansion plan. With an eye on the potential of the UAE’s investor base, eToro seeks to extend its business beyond just providing trading opportunities. The company is committed to fostering financial education and encouraging community engagement among its users in the region.The latest issuance of a full license by the ADGM is the culmination of an initial in-principle authorization obtained over a year ago, showcasing a deliberate approach to regulatory compliance. eToro Founder and CEO Yoni Assia commented on the development in a press release, stating:“The approval of our operating license by ADGM is a key milestone in our continued global expansion. Abu Dhabi is increasingly recognized as a growing fintech hub, and we are excited to become part of this flourishing ecosystem.”M2 primed to onboard retail and institutional clientsSimultaneously, cryptocurrency exchange M2 has also been recognized by the ADGM, earning the status of a fully regulated Multilateral Trading Facility and custodian. M2 is now permitted by this license to serve both retail and institutional clients in the UAE, offering services such as crypto custody, UAE dirham-based Bitcoin and Ethereum trading and on/off-ramp services for the dirham (AED).Stefan Kimmel, CEO of M2, considers the timing of this license as particularly advantageous, coinciding with a renewed positive sentiment among investors. M2’s range of services in the UAE market is designed for diverse client groups, addressing the needs of both retail and institutional investors.Official platform launchIn rolling out its service offering in Abu Dhabi, the trading and custodial services platform has partnered with Abu Dhabi Commercial Bank (ADCB). Commencing this week, both retail and institutional clients within the UAE can now register on the M2 platform.The firm will offer custody and trading of digital assets while also extending yield-bearing products of up to 10.5% on BTC and ETH.The strategic geographical location, business-friendly environment and forward-thinking regulatory approach make the UAE an attractive destination for international crypto players seeking operational licenses. Earlier this month, the ADGM’s registration authority introduced comprehensive regulations, particularly focusing on Web3 organizations. The regulatory framework has focused in particular on distributed ledger technology (DLT)-oriented foundations and decentralized autonomous organizations (DAOs).The successful acquisition of ADGM licenses by eToro and M2 marks a significant milestone for both entities. As these platforms introduce their innovative services to the region, the UAE is poised to play a central role in shaping the future of cryptocurrency.

news
Policy & Regulation·

Jan 25, 2024

ACE Exchange in turmoil as Taiwanese prosecutors broaden investigation

Taiwanese prosecutors have expanded their inquiry into ACE Exchange, urging the detention of Chenhuan Wang, the platform's president and partner at Chien Yeh Law Offices. The Taipei District Prosecutors Office disclosed to The Block that Wang, alongside four other suspects, was summoned after police raids in Northern Taiwan earlier this month. Subsequent to the interrogation, prosecutors sought Wang's detention and restrictions on visitation rights, alleging his involvement in money laundering and fraud linked to the activities orchestrated by the detained founder, David Pan. Chien Yeh Law Offices has moved to distance itself from its partner’s activities, stating that the matter is a personal investment of Wang’s. It stated:”Ace Digital Innovation Co., Ltd. is the personal external investment affairs of lawyer Wang Chenhuan and has nothing to do with the firm.”Photo by Thomas Tucker on UnsplashMisleading advertisingPan, along with colleague Lin Nan, is accused of a three-year collaboration, utilizing misleading social media advertisements to deceive investors into acquiring worthless cryptocurrencies, including MOCT. The inclusion of Wang in the investigation now requires a court determination on potential detention. ACE Exchange responded to Pan's arrest earlier, asserting that Pan had ceased daily operations in 2022, with Wang assuming the presidency in September 2023. Wang claimed to have initiated efforts to delist controversial coins, with ACE assuring cooperation with investigations as a witness. The exchange affirmed the normalcy of trading and operational conditions, emphasizing the security of user assets and smooth cryptocurrency and New Taiwan dollar deposit and withdrawal services. Established in 2018, ACE Exchange ranks among Taiwan's prominent crypto exchanges, alongside BitoGroup and MaiCoin. In spite of alleged wrongdoing relative to key actors within the business, the platform has outlined its commitment to legal principles, stating zero tolerance for any misconduct within its management team. Regulatory focus on offshore exchangesIn the broader context of Taiwan's crypto landscape, the Financial Supervisory Commission (FSC) plans to impose restrictions on offshore cryptocurrency exchanges operating within its jurisdiction, unless they secure required registration. In September last year, the FSC drafted guiding principles for virtual asset service providers (VASPs). These guidelines aim to fortify information disclosure, set review standards for virtual asset listing and delisting and ensure the secure separation of companies' and customers' assets. The FSC intends to strictly prohibit illegal business solicitation by foreign crypto firms, mandating registration and compliance declarations with anti-money laundering regulations. Failure to comply will result in the prohibition of business solicitation within Taiwan or from domestic residents by foreign VASPs. As Taiwanese prosecutors intensify their efforts, the ACE Exchange case unfolds as a critical episode in the evolving regulatory landscape, prompting both legal scrutiny and a reevaluation of the country's approach to crypto oversight.  

news
Policy & Regulation·

Jan 07, 2025

Regulatory approach sees Singapore move closer to crypto hub status

Crypto licensing developments in Singapore over the course of 2024, allied with feedback from industry insiders, suggest that the city-state has furthered its development as a crypto industry hub in the Asia-Pacific (APAC) region.Photo by Mike Enerio on UnsplashDoubling up on licensing issuanceAccording to a report published by Lianhe Zaobao, a Chinese language newspaper in Singapore, the Monetary Authority of Singapore (MAS), had issued twice the number of Major Payment Institution (MPI) licenses in 2024 by comparison with the previous year. Four licenses were issued in 2023 to Crypto.com, Coinbase, Ripple and Blockchain.com. That compares with 13 licenses issued in 2024 to companies such as GSR, BitGo, Anchorage, Upbit and OKX. This uptick in licensing signals a regulatory regime that is innovation-friendly, resulting in Singapore becoming a key destination for startup companies in the crypto and Web3 space. Risk-adjusted regulatory approachAccording to William Croisettier, chief growth officer at ZKCandy, Singapore is primed to continue its development as a leading crypto hub for Web3 businesses within the APAC region. ZKCandy is a gaming-focused hyperchain within the zkSync ecosystem that has developed due to a collaboration between the Ethereum layer-2 zkSync network and Southeast Asia’s largest gaming developer, iCandy. Croisettier spoke to Cointelegraph on the matter recently, stating: “The country adopts a risk-adjusted approach to crypto regulation, focusing on the biggest digital currencies to protect investors. Singapore also makes it easy for new crypto firms to interact with local banking partners, a provision considered a luxury in other parts of the world.” Mouloukou Sanoh, co-founder and CEO of Dubai-based Mansa Finance, a DeFi platform that provides liquidity to cross-border payment companies, has also spoken positively about Singapore’s status within the crypto sector. Sanoh stated: “With its clear regulations and support for innovation, Singapore attracts top companies and talent, fostering a thriving ecosystem. This proactive approach signals a strong commitment to digital finance, contrasting with Hong Kong's more cautious stance.” Positive study findingsThese views correlate with a recent study carried out by ApeX Protocol, a multi-chain liquidity platform. The study applied a ranking to ten jurisdictions based on factors such as jobs created in the blockchain field, the number of crypto exchanges located within a jurisdiction and the number of blockchain-related patents filed. On that basis, it found that Singapore topped the rankings, ahead of Hong Kong in second place. Singapore was found to have 81 crypto exchanges located within the city-state, over 1,600 blockchain-related patents filed and 2,433 crypto-sector jobs created. A recent survey conducted by CoinDesk found that from a crypto adoption perspective, Thailand, followed by the United Arab Emirates (UAE) and India, lead the APAC region. Of the 10 countries surveyed, Singapore weighed in in seventh place with a 23% adoption rate, just one percentage point behind Hong Kong with 24%. As Hong Kong and Singapore compete to attract crypto-related business, both still have room for improvement when it comes to the crypto adoption metric in comparison with other Asian countries. 

news
Loading