Top

Singaporean authorities alert businesses to Bitcoin ransomware risk

Policy & Regulation·June 11, 2024, 6:07 AM

Akira ransomware, responsible for stealing $42 million from over 250 organizations across North America, Europe and Australia in just a year, is now targeting businesses in Singapore. In response, Singaporean authorities have issued a joint advisory warning local businesses about the increasing threat posed by a variant of this ransomware.

https://asset.coinness.com/en/news/2a60ac3f2278d1ab842181ec0c178bfb.webp
Photo by Mike Enerio on Unsplash

Alert follows complaints

The alert follows multiple complaints from victims, prompting agencies like the Cyber Security Agency of Singapore (CSA), the Singapore Police Force (SPF) and the Personal Data Protection Commission (PDPC) to take action. These agencies emphasize the urgency of recognizing and combating this threat.

 

How Akira operates

Akira affiliates employ various techniques to infiltrate a victim's network. These include exploiting known vulernabilities. For example, that could mean the targeting of services like Cisco virtual private networks (VPNs) that have been configured without multi-factor authentication (MFA).

 

Another approach that the ransomware incorporates is attacking external-facing services such as the Remote Desktop Protocol (RDP) via brute force. Social engineering is another tool within its repertoire. This involves tricking victims into downloading malicious software or entering credentials on phishing websites.

 

There is a marketplace for compromised credentials in the dark web. Akira also relies on such data, acquiring it from access brokers who sell network access. 

 

Once inside a network, Akira affiliates often create new domain accounts to maintain persistent access, even after reboots. They use numerous tools to steal user credentials, escalate privileges and spread throughout the network.

 

Detection and prevention measures

The Singaporean advisory outlines several strategies for detecting, deterring and neutralizing Akira attacks. Authorities strongly advise against paying ransoms, on the basis that doing so does not guarantee data recovery or prevent future attacks.

 

Authorities also warn that paying ransoms can encourage further attacks. The FBI has noted that Akira operators do not contact victims. Instead, they expect victims to initiate contact.

 

Payment in Bitcoin

The advisory outlines how Bitcoin is implicated in the ransomware scam. It states:

”Ransom payments are requested in Bitcoin, which are directed to cryptocurrency wallet addresses specified by the affiliates. The TOR site (.onion) where victims contact the affiliates, contains stolen information and a list of the affected organisations.”

 

It’s not the first time that Singaporean authorities have issued warnings that have implicated Bitcoin and crypto. In January, the CSA and SPF, in a joint advisory, suggested that people should use hardware wallets in an effort to guard against crypto-related malware and phishing attacks.

 

A number of weeks prior to that, Singapore’s former Prime Minister, Lee Hsien Loong, took to Facebook to issue a warning with regard to a crypto scam that involved the use of deceptive content generated using artificial intelligence (AI).

 

Mitigation techniques

Businesses are being urged by the authorities to adopt best practices to mitigate the Akira ransomware threat. They suggest the implementation of a recovery plan alongside the use of multi-factor authentication (MFA) in order to secure data and the access to that data. 

 

They also suggest filtering network traffic as it helps in identifying and blocking malicious activities. Meanwhile, disabling unused ports and hyperlinks curbs the risk further as it reduces the attack surface. Lastly, the authorities suggested the use of system-wide encryption to protect data even if it is accessed by unauthorized entities.

More to Read
View All
Web3 & Enterprise·

Nov 11, 2023

UBS extends crypto ETF access to clients in Hong Kong

UBS extends crypto ETF access to clients in Hong KongMultinational investment bank UBS Group AG has followed suit with competitors like HSBC, enabling its wealthy clients in Hong Kong to engage in the trading of select crypto-linked exchange-traded funds (ETFs).Photo by Pierre Borthiry — Peiobty on UnsplashRegulatory approval to offer three ETFsThis move, reported by Bloomberg on Thursday, aligns with Hong Kong’s efforts to establish itself as a prominent digital asset hub. Citing an undisclosed source, Bloomberg outlined that three crypto ETFs, namely the Samsung Bitcoin Futures Active, CSOP Bitcoin Futures and CSOP Ether Futures, have received approval from the Securities and Futures Commission (SFC) and will be available on UBS’s Hong Kong platform starting this Friday.The inclusion of these ETFs allows UBS clients to diversify their investment portfolios, offering exposure to the dynamic crypto market. Educational materials will also be accessible to clients, aiding in their understanding of associated risks. While UBS declined to comment on this development, it marks a strategic move by the Swiss bank to tap into the growing demand for crypto-related investment products.In June, Hong Kong’s largest bank, HSBC, moved to expand its offering to include crypto ETFs. It has made available the very same crypto ETFs as UBS is about to offer.Hong Kong’s crypto credentialsHong Kong introduced a comprehensive digital asset regulatory regime on June 1, aiming to safeguard investors while fostering the Chinese autonomous territory’s emergence as a digital financial center. The SFC permits retail investors to trade major tokens on licensed exchanges under these regulations.Despite these regulatory advancements, Hong Kong faced setbacks, notably with the recent issues surrounding the unlicensed JPEX exchange, which led to increased scrutiny. The establishment of a joint task force between the SFC and the police aims to monitor and prevent suspicious activities within the crypto industry.Globally, financial institutions remain cautious about compliance risks in the crypto sector. However, signs of increased engagement are emerging. DBS, Singapore’s largest bank, has expressed its intention to seek a license to offer crypto services to Hong Kong customers. ZA Bank, the largest virtual bank in Hong Kong, plans to provide token-to-fiat currency conversions over licensed platforms. Furthermore, SEBA Bank, backed by the Julius Baer Group, has obtained a license for its unit to offer crypto services in Hong Kong.Unlocking ETF potentialA report published by the Hong Kong Stock Exchange in April claimed that crypto ETFs possess the potential to unlock the next phase of digital asset expansion in Asia. Earlier this week, it emerged that regulators were open to the notion of allowing retail access to spot crypto ETFs in Hong Kong, provided that the necessary regulatory approvals and checks were in place.The inclusion of the CSOP Bitcoin Futures and CSOP Ether Futures funds on UBS’s platform highlights the gradual recovery of the crypto sector from the market rout experienced in 2022. Despite the previous market challenges and collapses, the prospect of the U.S. allowing its first spot Bitcoin ETFs has contributed to a resurgence in the largest token’s price this year. The move by UBS aligns with the broader trend of financial institutions cautiously embracing the crypto economy, indicating a shifting attitude toward these digital assets in the financial mainstream.

news
Web3 & Enterprise·

Nov 03, 2023

Dubai’s VARA grants WadzPay ‘initial approval’ of trading license

Dubai’s VARA grants WadzPay ‘initial approval’ of trading licenseIn the latest demonstration of the emirate’s crypto-friendly credentials, Dubai regulator, the Virtual Assets Regulatory Authority (VARA), has granted an “Initial Approval” license to WadzPay.WadzPay was founded in 2018 in Singapore as a business-to-business (B2B) technology firm that concentrates its efforts on enabling digital asset-based transaction processing and settlement. This licensing approval is a significant step forward for the startup, as it inches closer to obtaining a full-fledged Virtual Asset Service Provider (VASP) license.Photo by Paul MARSAN on UnsplashGearing up for service roll-outWith this approval in hand, WadzPay is gearing up to offer a range of virtual asset services, specifically under the forthcoming VASP License for Transfer and Settlement, as well as Broker-Dealer trading activities.That said, the current VARA license places certain restrictions on WadzPay’s offerings. While WadzPay is known for providing a wide array of services to businesses (B2B) and individual users through its B2B2C platform, the “Initial Approval” license limits its scope to only a subset of its virtual asset products and services.Flurry of approvalsDubai has taken center stage in the realm of crypto-friendly jurisdictions, granting a flurry of operational licenses to numerous crypto firms and exchanges in recent months. The regulatory framework in Dubai is underpinned by robust guidelines for VASPs. To operate fully within this framework, crypto firms must navigate a meticulous three-tier licensing process, starting with provisional approval, followed by a minimal viable product (MVP) license, culminating in a total market product license.One of the recent beneficiaries of VARA’s approvals is Backpack, a virtual currency wallet provider. Last month, Backpack received its VASP license, allowing the introduction of the Backpack Exchange to the market. However, similar to WadzPay’s situation, Backpack’s license comes with certain limitations.It permits the offering of crypto exchange services within Dubai but restricts the rollout of other virtual asset services. The Backpack Exchange sets itself apart with advanced features, including zero-knowledge (ZK) proof-of-reserves, multi-party computation (MPC) for secure custody and lightning-fast order execution capabilities.Nomura portfolio company approvalsKomainu, a collaborative venture involving financial heavyweights like Nomura, CoinShares and Ledger, is another notable success story. After a diligent licensing journey, Komainu secured its full operating license from VARA, approximately 10 months after obtaining its MVP license in November 2022.Laser Digital, a crypto division under the vast umbrella of financial giant Nomura, also earned its operational license from VARA in August. Through its dedicated subsidiary, Laser Digital Middle East FZE, based conveniently in Dubai, Nomura has showcased its VASP license. The permit enables the firm to offer a suite of services, including brokerage, virtual asset management and investment offerings within the emirate.Notably, Laser Digital’s licensure followed closely on the heels of Binance, the global crypto exchange. Binance secured its operational minimum viable product (MVP) license from VARA, paving the way for providing crypto exchange and virtual asset broker-dealer services within the region.This flurry of licensing activities and approvals in Dubai is suggestive of the emirate’s commitment to fostering a progressive and regulated crypto environment.

news
Web3 & Enterprise·

Dec 21, 2024

Crypto.com adds AED support in the UAE

Crypto.com, the global crypto exchange platform headquartered in Singapore, has recently added an “AED Fiat Wallet,” allowing its users based in the United Arab Emirates (UAE) to deposit and withdraw UAE dirhams to and from their Crypto.com accounts. In a statement published on its website on Dec. 11, the firm outlined details of the added feature. So as to be able to access the AED Fiat Wallet, UAE residents will need to be registered on the platform with a UAE phone number. Once users configure platform settings to reflect the AED as their default currency, the platform displays the relevant deposit information to enable users to deposit the currency to their accounts. The minimum deposit has been set at 10 AED per transaction with a maximum of four million AED per day.Photo by Katerina Kerdi on UnsplashFacilitated by Standard CharteredCrypto.com claimed on X that the new feature could be set up easily, enabling fast and simple transfers. Additionally, the company is not charging users a deposit fee for AED deposits. Tarik Erk, Crypto.com’s General Manager for Middle East & Africa, explained that a collaboration with British multinational bank Standard Chartered had enabled the offering. Erk stated: “This new wallet launch is made possible through our global banking partnership with Standard Chartered which we announced in August, alongside the ongoing and valued support of VARA [Virtual Assets Regulatory Authority], which enables us to continue our expansion across the UAE. We’re extremely focused on offering our customers a seamless world-class experience and, at its very core, that includes ease of deposits and withdrawals – enabling our customers to interact with our products and services with as much flexibility as possible.” Crypto.com launched its service in the UAE in August, and at the time, it recognized the significance of its partnership with Standard Chartered. In September Standard Chartered announced the launch of crypto custody services in the UAE in collaboration with Brevan Howard Digital. The service was licensed by the Dubai Financial Services Authority (DFSA).  In November of last year, Crypto.com was awarded a license by VARA to provide virtual asset services. Last week, it emerged that the company had acquired Orion Principals Limited, an Abu Dhabi-based securities firm. The brokerage firm is licensed by the local regulator within the Abu Dhabi Global Market, an economic free zone and financial center. Crypto.com said that the acquisition will lead to the company rolling out new services to eligible platform users, including securities, options, futures and contracts for difference. Deutsche Bank partnershipHaving forged a partnership with TradFi banking giant Standard Chartered in the Middle East, Crypto.com announced a similar partnership with another TradFi giant, Deutsche Bank, last week. The collaboration will see Deutsche Bank provide the company with banking support and corporate banking services within its home base of Singapore, as well as in Australia and Hong Kong. Back in June, Deutsche Bank partnered with another crypto exchange business, Bitpanda, to assist it in offering real-time inbound and outbound payments on its platform. 

news
Loading