Top

Kaspersky Says Crypto Phishing on the Rise in the Philippines

Policy & Regulation·July 13, 2023, 12:55 AM

The Philippines witnessed a significant increase in detected cryptocurrency-related attacks last year while Vietnam recorded the highest level in Southeast Asia, according to cybersecurity firm Kaspersky.

Photo by Markus Spiske on Unsplash

 

Ease of crypto access

Vietnam topped the list with over 64,000 detections. Meanwhile, the Philippines recorded 24,737 cases of crypto-phishing attacks in 2022, up from 9,164 cases in 2021, making it the second-highest number in Southeast Asia.

Adrian Hia, Managing Director for Asia Pacific at Kaspersky, attributed the rise to the ease of accessing cryptocurrency in the Philippines. He explained that as users increasingly turn to mobile devices, they are inadvertently exposing themselves to potential breaches, as malware can be installed through various touch points.

Research published by Malaysian crypto data aggregator, CoinGecko, earlier this month, also points to the Philippines as having the second highest level of interest in crypto in Southeast Asia, after Singapore.

 

Targeting popular platforms

Cybercriminals commonly target accounts of popular online gaming platforms and crypto wallets using advanced stealers or “stalkerware” that allow them to spy on individuals through their mobile devices, Kaspersky stated. The firm’s monitoring data revealed that malware is spreading through legitimate channels such as official marketplaces and advertisements in popular apps.

Across Southeast Asia, the total number of crypto-phishing detections decreased to 147,649 in 2022 from 164,330 in 2021, according to Kaspersky. However, only Singapore (down 74%), Thailand (down 51%), and Vietnam (down 15%) observed declines in detections. Besides the Philippines, crypto-related attacks also increased in Indonesia (from 19,584 in 2021 to 24,642 in 2022) and Malaysia (from 16,071 to 16,767).

Kaspersky discovered an average of 400,003 new malicious files per day in 2022, representing an increase of 20,000 files per day compared to the previous year. Hia emphasized that scammers are relentless in their efforts to steal cryptocurrency due to its increasing popularity and adoption, particularly in Southeast Asia. He urged cryptocurrency adopters in the region to stay informed about the latest tricks used by crypto phishers to protect their digital assets.

 

Email-based attacks

Roman Dedenok, a spam analysis expert at Kaspersky, revealed that crypto phishers often employ email-based attacks to target crypto users. He explained that scammers entice victims with the prospect of participating in a cryptocurrency giveaway, offering popular digital assets such as Bitcoin, Ethereum, Litecoin, Tron, or Ripple.

The scammers provide a three-point guide to claim the free cryptocurrency along with a link to the “promotion” website. Clicking on the link leads users to a phishing site where they are prompted to specify the wallet to which they want the funds transferred.

In response to the growing cybersecurity concerns, Kaspersky is engaging in discussions with government institutions worldwide. In the Philippines, while the central bank does not directly regulate cryptocurrency, it has established guidelines for virtual asset service providers. The Chairman of the Securities and Exchange Commission (SEC) in the Philippines, Emilio Aquino, recently delayed publication of a regulatory framework for crypto, on the basis of having “to make sure people don’t get burned.”

Entities involved with virtual assets are required to obtain a license from the Bangko Sentral ng Pilipinas, the central bank of the Philippines, to comply with regulations.

More to Read
View All
Web3 & Enterprise·

Dec 28, 2023

PiLab Technology and Mirae Asset Securities to build Web3 infrastructure to navigate tokenized securities market

Blockchain firm PiLab Technology has signed a strategic memorandum of understanding (MOU) with Mirae Asset Securities to collaborate on creating Web3 infrastructure – namely Web3 technology for identity authentication – and identify asset management trends in the Web3 sphere. This comes in an effort to establish leverage in the emerging tokenized securities market, according to Korean news outlet The Block Post on Thursday (KST).Photo by GuerrillaBuzz on Unsplash"Through our collaboration with Mirae Asset Securities, we expect to play a major role in the convergence of blockchain technology and financial markets," said Park Do-hyun, CEO of PiLab Technology. "PiLab Technology will continue to lead the way in making Web3 services more user-friendly." Financial giants uniteMirae Asset Securities is the largest investment banking and stock brokerage company by market capitalization in South Korea. The firm previously co-founded a financial innovation consortium with telecommunications conglomerate SK Telecom called Next Finance Initiative, which is preparing to issue tokenized securities by operating a token securities working group on a global blockchain network. Hana Financial Group also recently joined the consortium as a member company. Pioneering services in Web3Meanwhile, PiLab Technology operates its own multichain network called Bifrost, which houses a deposit and lending DeFi service called BiFi. The company has previously raised KRW 14 billion (approximately $10.9 million) in funding from venture capital firms like Korea Investment Partners and more. Last month, PiLab teamed up with the Korea Information Certificate Authority (KICA) and Travel Rule solutions provider CODE to establish an authentication system to advance the country’s Web3 environment. 

news
Web3 & Enterprise·

Aug 28, 2023

Infinite Block Receives Certification for Information Security Management System of Blockchain…

Infinite Block Receives Certification for Information Security Management System of Blockchain PlatformSouth Korean blockchain fintech company Infinite Block announced on Monday that it has obtained ISO 27001 certification for the information security management system of its upcoming blockchain platform from Lloyd’s Register Quality Assurance (LRQA), a UK-based global assurance provider.Ramping up information securityISO 27001 is an international standard established by the International Organization for Standardization (ISO) for managing information security. It enables companies and organizations to establish a system that manages information security, cybersecurity, and privacy protection, thereby proving to their customers and partners that they protect important and personal data.Photo by Towfiqu barbhuiya on UnsplashThis latest development comes after the company recently received approval from the Korean Financial Services Commission to function as a virtual asset service provider (VASP), becoming the 37th entity to do so in Korea.“Although we are still a fledgling startup, we have made consistent efforts to establish an information security management system since our inception,” said Jeong Gu-tae, CEO of Infinite Block. “This certification is a testament to our dedication.”Comprehensive blockchain platformInfinite Block is currently developing a blockchain platform set to be launched soon that offers integrated support for virtual asset custody services, including transferring, storing, and managing virtual assets. It also supports various blockchain mainnets and tokens, including Bitcoin, Ethereum, Klaytn, Tezos, Polygon, and Avalanche.“We will continue to enhance and improve our information security system to further solidify user trust,” CEO Jeong added.

news
Web3 & Enterprise·

Jun 20, 2023

Conflict Identified as Crypto.com Trading on its Own Platform

Conflict Identified as Crypto.com Trading on its Own PlatformTrading practices at Crypto.com, the Singapore-based cryptocurrency exchange, have raised questions about potential conflicts of interest within the digital assets industry.Citing a number of unnamed sources, the Financial Times (FT) made the claim in a report published on Monday.Photo by Pixabay on PexelsConflict of interestIn traditional financial markets, exchanges typically match buyers with sellers at competitive transparent prices, while market making and proprietary trading are conducted by separate private companies. However, US regulators have recently cracked down on similar activities at digital asset exchanges. Binance, the world’s largest crypto exchange, faced 13 charges from the US Securities and Exchange Commission (SEC), including allegations of manipulative trading to inflate trading volume.The presence of internal traders at Crypto.com has not been widely known since the company’s launch in 2016. The FT’s sources claim that Crypto.com executives provided sworn statements to external trading houses denying the company’s involvement in trading activities.Employees were allegedly instructed to deny the existence of an internal market-making operation. In response to inquiries, Crypto.com denied that employees were asked to lie, stating that their internal market maker functioned similarly to third-party market makers, ensuring tight spreads and efficient markets on their platform.The majority of Crypto.com’s revenue reportedly comes from its app for retail traders, where the company acts as the counterparty for transactions and operates as a broker model. The company’s trading team hedges these positions on various venues, including their own exchange, to maintain risk neutrality. Crypto.com emphasized that their exchange provides a level playing field for institutional traders.According to insiders, Crypto.com’s proprietary trading desk engages in trading activities on the company’s exchange and other platforms, solely focused on generating profits rather than facilitating an exchange. The market making desk, on the other hand, aims to enhance liquidity on the platform.Not a revenue sourceCrypto.com defended its practices by stating that comparing trading volumes to competitors is common in the industry. It said that the company’s priority is to continuously improve order book liquidity and reduce spreads, benefiting all participants. The firm told Decrypt that trading is not a source of revenue: “While we do have some market making activity, for example, we have internal market makers for our CFTC-regulated product Up/Downs in the United States.”As a private company, Crypto.com publishes accounts in different countries, but revenue breakdown by business line is not disclosed.Closure of institutional tradingFollowing the SEC’s enforcement actions, earlier this month Crypto.com announced the closure of its exchange for institutional US traders due to limited demand in the current market landscape, effective from June 21.In any marketplace transparency and fairness are crucial. It’s fair to say that there has been some level of sharp practice among some actors in the marketplace while regulators have been lacking in getting up to speed with the emergent sector, and moving to protect consumers. With the major crypto platform failures of 2022 has come renewed interest in resolving these issues. That may make for some short-term difficulty, but in the longer term, it should mean greater protections for market participants so long as a common sense approach is pursued.

news
Loading