Top

Singaporean authorities alert businesses to Bitcoin ransomware risk

Policy & Regulation·June 11, 2024, 6:07 AM

Akira ransomware, responsible for stealing $42 million from over 250 organizations across North America, Europe and Australia in just a year, is now targeting businesses in Singapore. In response, Singaporean authorities have issued a joint advisory warning local businesses about the increasing threat posed by a variant of this ransomware.

https://asset.coinness.com/en/news/2a60ac3f2278d1ab842181ec0c178bfb.webp
Photo by Mike Enerio on Unsplash

Alert follows complaints

The alert follows multiple complaints from victims, prompting agencies like the Cyber Security Agency of Singapore (CSA), the Singapore Police Force (SPF) and the Personal Data Protection Commission (PDPC) to take action. These agencies emphasize the urgency of recognizing and combating this threat.

 

How Akira operates

Akira affiliates employ various techniques to infiltrate a victim's network. These include exploiting known vulernabilities. For example, that could mean the targeting of services like Cisco virtual private networks (VPNs) that have been configured without multi-factor authentication (MFA).

 

Another approach that the ransomware incorporates is attacking external-facing services such as the Remote Desktop Protocol (RDP) via brute force. Social engineering is another tool within its repertoire. This involves tricking victims into downloading malicious software or entering credentials on phishing websites.

 

There is a marketplace for compromised credentials in the dark web. Akira also relies on such data, acquiring it from access brokers who sell network access. 

 

Once inside a network, Akira affiliates often create new domain accounts to maintain persistent access, even after reboots. They use numerous tools to steal user credentials, escalate privileges and spread throughout the network.

 

Detection and prevention measures

The Singaporean advisory outlines several strategies for detecting, deterring and neutralizing Akira attacks. Authorities strongly advise against paying ransoms, on the basis that doing so does not guarantee data recovery or prevent future attacks.

 

Authorities also warn that paying ransoms can encourage further attacks. The FBI has noted that Akira operators do not contact victims. Instead, they expect victims to initiate contact.

 

Payment in Bitcoin

The advisory outlines how Bitcoin is implicated in the ransomware scam. It states:

”Ransom payments are requested in Bitcoin, which are directed to cryptocurrency wallet addresses specified by the affiliates. The TOR site (.onion) where victims contact the affiliates, contains stolen information and a list of the affected organisations.”

 

It’s not the first time that Singaporean authorities have issued warnings that have implicated Bitcoin and crypto. In January, the CSA and SPF, in a joint advisory, suggested that people should use hardware wallets in an effort to guard against crypto-related malware and phishing attacks.

 

A number of weeks prior to that, Singapore’s former Prime Minister, Lee Hsien Loong, took to Facebook to issue a warning with regard to a crypto scam that involved the use of deceptive content generated using artificial intelligence (AI).

 

Mitigation techniques

Businesses are being urged by the authorities to adopt best practices to mitigate the Akira ransomware threat. They suggest the implementation of a recovery plan alongside the use of multi-factor authentication (MFA) in order to secure data and the access to that data. 

 

They also suggest filtering network traffic as it helps in identifying and blocking malicious activities. Meanwhile, disabling unused ports and hyperlinks curbs the risk further as it reduces the attack surface. Lastly, the authorities suggested the use of system-wide encryption to protect data even if it is accessed by unauthorized entities.

More to Read
View All
Web3 & Enterprise·

Oct 11, 2023

Dunamu Restructures Leadership at Its Blockchain Research Arm

Dunamu Restructures Leadership at Its Blockchain Research ArmDunamu, the operator of South Korea’s largest cryptocurrency exchange Upbit, has implemented leadership changes at its blockchain research arm, Lambda256. That’s according to a report by local media outlet Decenter.Photo by Lea L on UnsplashCo-leadership structureStarting this month, Lambda256 welcomes a co-leadership structure, with tech maven Chung Ui-chung and financial specialist Park Yong-shin stepping in as co-CEOs. Each CEO holds independent signing authority. Chung previously held the role of Chief Technology Officer (CTO) at internet messaging giant Kakao, while Park Yong-shin boasts a distinguished career in public administration and finance, having passed the civil service examination and later steering the helm at Heungkuk Investment Trust Management, currently known as Heungkuk Asset Management.Tech expert and gov’t affairs specialistThe reshuffle follows the departure of former CEO Park Jae-hyun, who resigned last month. Shedding light on the division of roles, a Lambda256 official mentioned that Chung will spearhead practical endeavors, whereas Park Yong-shin will liaise with government sectors. Industry analysts perceive this strategic move as Lambda256’s intensified drive to hone its technological edge and navigate the evolving government regulations surrounding security tokens and associated blockchain ventures.Dunamu, holding a dominant 60.6% ownership in Lambda256, established the company in 2018, entrusting the leadership to Park Jae-hyun, a former employee of SK Telecom and Samsung Electronics. The subsequent year saw Lambda256 evolve into a subsidiary, rolling out blockchain platforms like Luniverse. However, financial challenges loomed, with the firm recording net losses of KRW 2.1 billion ($1.6 million) in 2020, KRW 3.7 billion in 2021, and KRW 46.5 billion in 2022.

news
Web3 & Enterprise·

Nov 16, 2023

Blockchain-powered donation platform collaborates with NPO Yana to hold charitable bazaar

Blockchain-powered donation platform collaborates with NPO Yana to hold charitable bazaarCherry, a blockchain-powered donation platform, is set to hold a bazaar with non-profit organization (NPO) Yana at POSCO CHANGeUP GROUND in Seoul from Friday to Saturday. The objective of this event is to support children’s homes and care leavers.Photo by Markus Winkler on UnsplashMedical expense support for children’s homesThe bazaar is being organized by ongoing sponsors of Cherry and Yana. This event will feature sales of corporate-sponsored items, with the proceeds dedicated to assisting with medical and various other expenses at children’s homes and for those who have left care. Visitors can look forward to an array of products from companies like Solideo Systems, Jungsaemmool Beauty, Esther Formula, and Rebuy For You. Moreover, the bazaar will showcase a collection of dresses and cherished items from celebrated personalities, including actresses Shin Ae-ra and Park Jin-hee, comedian Park Na-rae and Kpop singer Sandara Park.In addition to sponsored items, the bazaar will offer a wide range of items, including clothing, shoes, cosmetics, eyewear, and food. A representative from Cherry mentioned that all the vendors have committed to donating a part of their sales proceeds. This arrangement allows visitors to enjoy their shopping experience while also contributing to socially responsible consumption, as their purchases will lead to donations.Attendance at the bazaar is priced at KRW 10,000 (approximately $7.7), and registration for the event is available through the Cherry app. For those unable to attend in person, there’s still an opportunity to contribute by purchasing a ticket, allowing for donations from anywhere around the world.Blockchain transparencyCherry is Korea’s first blockchain-based donation platform, designed to foster a culture of transparent donations by recording all donation flows on the blockchain. Since its inception in 2019, the platform has attracted over 380 donor organizations running more than 1,900 campaigns. The cumulative donations have surpassed KRW 11 billion.Yana allocates 100% of its donations to support projects for children’s homes and individuals transitioning out of care. This commitment to transparency in their donation processes is facilitated through the use of the Cherry platform.

news
Web3 & Enterprise·

May 24, 2023

BitMEX Launches Bespoke Service in Hong Kong

BitMEX Launches Bespoke Service in Hong KongSeychelles-based cryptocurrency exchange and derivative trading platform BitMEX announced on Monday that it is launching a dedicated virtual asset service for its Hong Kong customers.The exchange published a blog post to its website in which it said that it is in the process of launching “BitMEX Hong Kong,” a dedicated service offering that will be set up on a transitional basis initially. The company is currently in the process of securing a virtual asset service provider (VASP) license from the Hong Kong regulator, the Securities Futures Commission (SFC). Licensing becomes effective in the Chinese autonomous territory on June 1.Photo by Karolina Grabowska on PexelsDedicated mobile appAmong the features the exchange intends to offer its Hong Kong-based customers is a bespoke app, catering specifically to users in the city. The platform will offer Hongkongers the ability to buy and sell cryptocurrencies with eleven spot trading pairs. From an on-boarding and off-boarding perspective, the firm will facilitate the conversion of cryptocurrencies into over thirty fiat currencies.The company is looking to add value by offering additional services such as portfolio management and real-time deposits and withdrawals. BitMEX plans to enable additional functionality such as watchlists and detailed real-time data. Both of these features will enable service users to identify and follow crypto market trends.Licensing preparationsWhile the offering attempts to meet the specific needs of Hongkongers, it's likely that the main motivation relates to VASP licensing. The regulatory requirements in Hong Kong are likely to have distinct facets that would necessitate the company to tease out its service to Hong Kong citizens from its global platform.The SFC has indicated on Tuesday that it will enable crypto trading for retail investors. Notwithstanding that, it’s not doing that without the incorporation of several measures to protect the interests of retail users. Any promotions or incentives that lead a marketing effort with free gifts, and this will likely include token airdrops, will be prohibited.Minimum capital liquidity requirements are being set. Furthermore, client assets will have to be segregated from exchange assets, although the Commission doesn’t mind if the VASP simply segregates said funds itself or does so by way of using an escrow service.Stephan Lutz, acting CEO and group CFO at Bitmex, commented on the development: “We are optimistic that Hong Kong will achieve its ambition of becoming a world-leading Web3 role model city and potentially the Web3 hub for China in years to come.”On May 29, the firm will transfer existing Hong Kong-based customers from its global platform to its new affiliated Hong Kong entity, HDR BMEX Limited. Remaining account balances will be transferred over on that date. There will be no requirement for Hong Kong-based users to undertake additional KYC (know-your-customer) checks or account verification.Earlier this month, the exchange added two additional digital assets ($SUI & $PEPE) to its range of available perpetual contracts.

news
Loading