Top

Singaporean authorities alert businesses to Bitcoin ransomware risk

Policy & Regulation·June 11, 2024, 6:07 AM

Akira ransomware, responsible for stealing $42 million from over 250 organizations across North America, Europe and Australia in just a year, is now targeting businesses in Singapore. In response, Singaporean authorities have issued a joint advisory warning local businesses about the increasing threat posed by a variant of this ransomware.

https://asset.coinness.com/en/news/2a60ac3f2278d1ab842181ec0c178bfb.webp
Photo by Mike Enerio on Unsplash

Alert follows complaints

The alert follows multiple complaints from victims, prompting agencies like the Cyber Security Agency of Singapore (CSA), the Singapore Police Force (SPF) and the Personal Data Protection Commission (PDPC) to take action. These agencies emphasize the urgency of recognizing and combating this threat.

 

How Akira operates

Akira affiliates employ various techniques to infiltrate a victim's network. These include exploiting known vulernabilities. For example, that could mean the targeting of services like Cisco virtual private networks (VPNs) that have been configured without multi-factor authentication (MFA).

 

Another approach that the ransomware incorporates is attacking external-facing services such as the Remote Desktop Protocol (RDP) via brute force. Social engineering is another tool within its repertoire. This involves tricking victims into downloading malicious software or entering credentials on phishing websites.

 

There is a marketplace for compromised credentials in the dark web. Akira also relies on such data, acquiring it from access brokers who sell network access. 

 

Once inside a network, Akira affiliates often create new domain accounts to maintain persistent access, even after reboots. They use numerous tools to steal user credentials, escalate privileges and spread throughout the network.

 

Detection and prevention measures

The Singaporean advisory outlines several strategies for detecting, deterring and neutralizing Akira attacks. Authorities strongly advise against paying ransoms, on the basis that doing so does not guarantee data recovery or prevent future attacks.

 

Authorities also warn that paying ransoms can encourage further attacks. The FBI has noted that Akira operators do not contact victims. Instead, they expect victims to initiate contact.

 

Payment in Bitcoin

The advisory outlines how Bitcoin is implicated in the ransomware scam. It states:

”Ransom payments are requested in Bitcoin, which are directed to cryptocurrency wallet addresses specified by the affiliates. The TOR site (.onion) where victims contact the affiliates, contains stolen information and a list of the affected organisations.”

 

It’s not the first time that Singaporean authorities have issued warnings that have implicated Bitcoin and crypto. In January, the CSA and SPF, in a joint advisory, suggested that people should use hardware wallets in an effort to guard against crypto-related malware and phishing attacks.

 

A number of weeks prior to that, Singapore’s former Prime Minister, Lee Hsien Loong, took to Facebook to issue a warning with regard to a crypto scam that involved the use of deceptive content generated using artificial intelligence (AI).

 

Mitigation techniques

Businesses are being urged by the authorities to adopt best practices to mitigate the Akira ransomware threat. They suggest the implementation of a recovery plan alongside the use of multi-factor authentication (MFA) in order to secure data and the access to that data. 

 

They also suggest filtering network traffic as it helps in identifying and blocking malicious activities. Meanwhile, disabling unused ports and hyperlinks curbs the risk further as it reduces the attack surface. Lastly, the authorities suggested the use of system-wide encryption to protect data even if it is accessed by unauthorized entities.

More to Read
View All
Policy & Regulation·

Jun 14, 2023

Hong Kong Legislator Courting US Crypto Exchange Coinbase

Hong Kong Legislator Courting US Crypto Exchange CoinbaseRecently, Johnny Ng, a member of the Hong Kong Legislative Council, expressed his interest in the future development of Coinbase, a major US cryptocurrency exchange, in Hong Kong. In a tweet today, Ng said that he had been in contact with Coinbase and that he would keep the public updated on further progress.Photo by Ruslan Bardash on UnsplashNg’s invitation to crypto exchangesThis tweet follows Ng’s earlier invitation to Coinbase and other global crypto trading platforms to apply for licenses in Hong Kong. His comments are in line with Hong Kong’s efforts to become a hub for cryptocurrency and blockchain-related activities. As of June 1, a new licensing regime for centralized virtual asset trading platforms (VATPs) went into effect in the Chinese special administrative region.Differing opinionsDespite the enthusiasm shown by Ng, there are differing opinions on Hong Kong’s current suitability as a crypto-friendly jurisdiction. Leo Weese, the co-founder and President of the Bitcoin Association of Hong Kong, expressed reservations in an interview with crypto media outlet CoinDesk.Weese described Hong Kong’s current setup as “highly unattractive” for crypto businesses. He cited factors such as a relatively small and untested market, limited banking partnerships, and restrictive product offerings.Despite these challenges, Weese acknowledged some potential advantages, stating that Hong Kong’s classification of tokens as non-securities allows for the trading of securities that are deemed unregistered in other jurisdictions. It is important to note, however, that Weese cautioned against assuming that moving operations to Hong Kong would protect Coinbase from US regulatory measures.Moody’s altered outlook on CoinbaseMeanwhile, Moody’s, the American credit rating agency, recently revised Coinbase’s outlook from stable to negative, citing uncertainties surrounding the impact of the US Securities and Exchange Commission’s (SEC) charges on Coinbase’s operation as an unregistered securities broker.

news
Web3 & Enterprise·

Nov 09, 2023

Bithumb achieves top score in FIU anti-money laundering compliance evaluation

Bithumb achieves top score in FIU anti-money laundering compliance evaluationSouth Korean cryptocurrency exchange Bithumb revealed today (local time) that it received the highest score in its evaluation group during the anti-money laundering (AML) compliance evaluation conducted by the Financial Intelligence Unit (FIU) under the Financial Services Commission for the first half of the year.Photo by okaybuild on PixabayInternal control improvementsThe exchange received high marks for improving its AML internal control system, expanding the number of employees, boosting employee training measures and properly reporting suspicious transactions.In response to the evaluation results, Bithumb reaffirmed its dedication to implementing improvements in these areas. It also said that it would provide AML-related training for employees in other departments by encouraging them to obtain professional certifications in AML compliance standards.Plans for further system reinforcementThe exchange is also set to introduce a next-generation AML system early next year that applies machine learning techniques to analyze transaction patterns, thus enabling it to respond to money laundering activities — which have recently become more elaborate and sophisticated — faster and more effectively.“The results of this compliance system assessment are proof of the efforts and consideration of Bithumb’s employees,” said Choi Hee-kyung, a compliance officer at Bithumb. “With the next-generation AML system that we plan to implement next year, we look forward to establishing an advanced AML internal control system that thoroughly abides by domestic and international AML laws while effectively preventing and examining money laundering cases and risks of terrorist funding.”This comes after Flybit, another Korean crypto exchange, also recently revealed that it has received top ratings in a comprehensive AML evaluation by the FIU.

news
Web3 & Enterprise·

Dec 12, 2023

HTX experiences $258 million outflow post-hack

HTX experiences $258 million outflow post-hackHTX, the digital-asset trading platform associated with Chinese-born crypto mogul Justin Sun, has witnessed a substantial net outflow of $258 million since resuming operations after a significant security breach.According to Bloomberg, data from DefiLlama indicates that the outflow occurred between the exchange’s restart on Nov. 25 and Dec. 10, signaling unease among some clients following last month’s cyberattack. In November, HTX reported a loss of $30 million in crypto tokens due to the breach, prompting a temporary suspension of withdrawals and deposits.Towards the end of last month, the platform re-enabled withdrawal services for major cryptocurrencies, gradually bringing the exchange back to full service, supporting withdrawal of all digital assets.Photo by Amritanshu Sikdar on UnsplashMultiple hacksJustin Sun is also associated with the Poloniex exchange and the HECO Bridge, a network established by HTX for blockchain transfers. Both Poloniex and HECO fell victim to hacks in November, resulting in the theft of approximately $200 million in crypto. It’s worth noting that hackers had previously stolen $8 million from the HTX platform in September.HTX, which was formerly known as Huobi up until a business rebrand in September, boasts an average trading volume of $1.5 billion in the past 24 hours, securing its position as the fifteenth largest exchange when measured in terms of trading volume.Increased vigilanceIn the wake of several high-profile crypto platform failures in 2022, digital-asset investors are increasingly vigilant about monitoring flows and reserves at virtual currency exchanges. In particular, that trend gained momentum after the FTX platform’s collapse last year due to fraud.November turned out to be the most damaging month this year so far in terms of platform digital asset theft. Exit scams and exploits encountered during the month totaled a staggering $363 million in losses.In October, the UK’s Financial Conduct Authority (FCA) included HTX, alongside KuCoin, on a warning list, due to their promotion of services in the UK, without having obtained the required regulatory approvals.A third of reserves in BitcoinDefiLlama data reveals that Bitcoin constitutes the largest portion of HTX’s reserves, accounting for approximately 33%. Tron’s TRX token, launched by Sun in 2017, represents around 32% of the reserves. HTX’s native exchange coin, HT, makes up 14%, followed by a Sun-backed token named stUSDT at 12%.In August, Travis Kling, Founder of Ikigai Asset Management, had this warning relative to Sun and HTX:”Justin Sun is a criminal. There’s a hole in Huobi, a hole in TUSD and a hole in Tron DeFi. Act accordingly.”TRX, at the center of U.S. fraud allegations against Sun, prompted a March lawsuit by the Securities and Exchange Commission (SEC), accusing him and his firms of market manipulation to inflate the token’s trading activity. Sun dismissed the suit on the X social media platform back in March, stating that it “lacks merit.” On Sunday, Sun claimed that the Tron blockchain network which he founded had reached a new milestone of 200 million users.Despite security firm BlockSec reporting the recovery of the $8 million stolen in September, hackers still appear to control the $30 million taken last month. The ongoing situation raises concerns about the security measures and resilience of HTX in the face of persistent cyber threats.

news
Loading