Home Blog Page 118

Uniformed Engineers Gearing Up to Confront Hooded Cybercriminals in India

cyber warfare, cyber warfare whitepaper

According to a report from Computer Emergency and Response Team – India (CERT-In), India has recorded over 1.45 million cybersecurity incidents including breaches and hacks in the last five years. Out of this, 696,938 cybersecurity incidents took place in the first half of 2020 (till August) itself. Owing to the pandemic and the rapid digitization uptake, experts also believe that once the pandemic chaos settles, organizations will integrate cybersecurity in a bottom-up manner. This will create a huge demand for cybersecurity professionals in the country. However, this demand is not limited to private enterprises alone.

Ever since government operations and services went online, cybercrimes soared upwards. Now just the central, but also state governments in India are taking initiatives to deploy forces against it. One such initiative is Tamil Nadu’s deployment of cybercrime police stations.

Cybercrime Police Stations in Tamil Nadu

The state police force has identified around 185 engineers employed with the police department itself under various grades – from sub-inspectors to inspectors – to help them crackdown on the rising cybercrimes. This group of individuals come mainly from an engineering background in Electronics and Telecommunication and have undergone a rigorous training program of advanced investigation skills in cyber offenses. This additional training was carried out as a part of a joint initiative with the Indian Institute of Technology – Madras (IIT-M) and SSN College. The officers who have voluntarily agreed to join the core team will be deployed in 46 cybercrime police stations across all major cities including all Commissionerate and district police offices in the state.

The Commissioners or Superintendents of Police can always refer cybercrime complaints to these police stations. However, plans to soon have a State-level CyberCrime Wing are underway. This Wing would be headed by an officer equivalent to the rank of Additional Director-General of Police (ADGP), who would facilitate policy decisions and coordination with other agencies.

Security Tools and Training

Keeping an eye on the latest threat vectors, the state police force is also in talks with the Centre for Development of Advanced Computing (C-DAC) to procure the latest cyber forensic tools. Apart from this, the state police force plans to implement training programs at regular intervals “since capacity-building is a continuous process,” as quoted by a senior police official.

Related News:

Need for Cyber Training! Survey Finds Security Awareness Gaps in Indian Organizations

To know more about certified courses for becoming a cyber forensic investigator, click here.

Indian Government’s Botnet Cleaning and Malware Analysis Centre

We already spoke about the state-level initiative against cybercrimes. But apart from these macro-level initiatives, the Government of India, in association with CERT-In, is also trying to clean-up the cyberspace in the country. And to support this vision, it has launched the Cyber Swachhta Kendra (also known as the Botnet Cleaning and Malware Analysis Centre). The operations in this center are carried out by CERT-In under the provisions of Section 70B of the Information Technology Act, 2000. However, it is closely monitored by the Ministry of Electronics and Information Technology (MeitY).

Cyber Swachhta Kendra provides useful information, alerts, and tools that help them secure their devices against botnet and malware infections. It also has several free security tools from popular cybersecurity companies like eScan and Quick Heal, which can be downloaded from here.

Related News:

MicroWorld and CERT-In Collaborate to Enhance Overall Cybersecurity in India

Microsoft’s February 2021 Patch Tuesday is Here! Know Which Flaws are Fixed

Microsoft September 2021 Patch Tuesday

Microsoft released its monthly set of security updates as part of its February 2021 Patch Tuesday to fix over 56 security vulnerabilities affecting Windows TCP/IP implementation, including two Critical Remote Code Execution (RCE) vulnerabilities (CVE-2021-24074, CVE-2021-24094) and a Denial of Service (DoS) vulnerability (CVE-2021-24086). The three flaws are unique and require a separate patch process based on the exposure of an affected system.

If exploited, the vulnerabilities would allow a remote attacker to cause a stop error and users may receive a blue screen on their systems that are exposed online with minimal network traffic.

While there is no evidence that these vulnerabilities have been exploited, Microsoft urged users to patch the affected systems as early as possible due to the elevated risk associated with them. However, users who have enabled automatic updates are protected from these vulnerabilities.

“We believe attackers will be able to create DoS exploits much more quickly and expect all three issues might be exploited with a DoS attack shortly after release. Thus, we recommend customers move quickly to apply Windows security updates this month,” Microsoft said.

“These vulnerabilities were discovered by Microsoft as part of our continual focus on strengthening the security of our products. At this time, we have no evidence that these vulnerabilities were known to any third-party. These vulnerabilities result from a flaw in Microsoft’s implementation of TCP/IP and affect all Windows versions. Non-Microsoft implementations are not affected,” Microsoft added.

Last month Microsoft released the official patches for over 83 newly discovered vulnerabilities, marking the first of many for 2021. The security updates addressed flaws in around 11 of Microsoft’s products and services, including an actively exploited zero-day vulnerability. Out of 83 vulnerabilities, 10 were listed as critical, and 73 as important in severity.

Loss of Critical Data and Customers a Top Concern for APAC Businesses

106 million Thailand visitors

By now we all know that cloud technology adoption has skyrocketed and is considered the future for security solutions. Carrying this notion further, Barracuda, a provider of cloud-enabled security solutions, conducted a survey to dive deeper into understanding the adoption trends for public cloud, network and application vulnerabilities, and a variety of related security concerns to cloud technology.

 Key Highlights 

  • 76% of APAC respondents said they were targeted by a cyberattack at least once, highlighting a serious security challenge in the region.
  • Businesses are spending an average of seven hours on preventing and managing cyberattacks in APAC – which is the highest in the world.
  • 26% of APAC respondents quoted that the application security provided by cloud infrastructure is insufficient.
  • Loss of data and customers are top concerns when it comes to a successful cyberattack in APAC.
  • APAC respondents understand the need to protect applications that can be accessed by external users (86%), involve e-commerce or PII (89%), or can be accessed via mobile devices (90%).

The  survey was conducted by independent market researcher Vanson Bourne and includes responses from IT decision-makers who are responsible for their organization’s cloud infrastructure.

The survey report titled, “Securing Your Apps in the Borderless Cloud,” highlights the rising security challenge and associated costs in the APAC region. Overall, a 20% increase in cyberattacks has been observed in all geographic regions since 2017. However, when it comes to APAC, 76% of respondents reported being targeted by a cyberattack at least once, with 44% of them saying they have been attacked between 2 to 5 times. But even more surprising is a group of 22% who are not aware whether they have fallen victim to cyberattacks at all. In general, on average, organizations spend between 1-2 days per week on preventing and managing cyberattacks. But time spent on this work is highest in APAC – where the average is seven hours.

Other Findings

A third of APAC participants do not feel they are fully protected in the cloud, and data loss is always playing at the back of their minds. Additionally, despite the growing confidence in the public cloud, 95% of APAC respondents have added (56%) or plan to add (39%) extra security measures to their public cloud deployments. Other than this, more than half of APAC respondents (53%) are worried about losing sensitive, mission-critical data. In addition to data loss, interrupted operations due to the temporary shutdown of mission-critical applications (54%) in day-to-day business, and lost customers (50%) are top security concerns to APAC businesses when it comes to a successful cyberattack.

Image Credit: Barracuda

Organizations have also realized the potential risks of application vulnerabilities and the subsequent need to protect applications. 26% of APAC businesses find application security provided by the cloud infrastructure providers as insufficient. They believe that there is a need to add protection for applications that can be accessed by external users (86%), involve e-commerce or PII (89%), or can be accessed via mobile devices (90%).

James Forbes-May, Sales Vice President at Barracuda APAC, said, “As applications are rapidly becoming the most exploited threat vector, these security concerns underscore the importance to safeguard data with confidence by eliminating application vulnerabilities and stopping data breaches. By deploying a strong and secure web application firewall (WAF), organizations can be reassured about public cloud security and take advantage of all the business benefits inherent in leveraging the cloud.”

Related News:

Scammers Use Bots and Automation to Make Cyberattacks Effective: Barracuda Report

Barracuda Alerts APAC Holiday Shoppers of Possible Bot Attacks

LogoKit Phishing Kit Found Running on 700 Unique Domains

Phishing, phishing attacks

Threat actors are investing more in phishing kits to simplify and expand their phishing activities. Cybercriminals are developing new phishing strategies and exploring different attack avenues by leveraging innovative phishing kits, which are widely available on the dark web market. Their growing demand on the underground market resembles how attackers are reliant on these tools.

Security firm RiskIQ recently uncovered a new kind of phishing kit dubbed “LogoKit.” The new kit is designed to deploy malware easily and allows other attackers to reuse and adapt.

“Unlike many other phishing kits that take advantage of complex layouts and multiple files, the LogoKit family is an embeddable set of JavaScript functions. These kits are designed to interact within the Document Object Model (DOM)–the site’s presentation layer. Interacting with the DOM allows for the script to dynamically alter the visible content and HTML form data within a page without user interaction,” RiskIQ said.

How LogoKit Spreads?

  • Initially, the attacker sends an email ID, hidden with a specially crafted malicious URL.
  • Once a victim clicks on the URL, it redirects the user to a fake corporate web site.
  • The victim’s email is auto-filled into the email or username field to trick the users into thinking they have previously logged into the site.
  • If the victims enter their password, LogoKit sends the target’s email and password to an external source operated by threat actors.
  • LogoKit allows attackers to easily compromise websites and embed the malware or malicious script in them.

RiskIQ claimed that LogoKit uses simple login forms to dupe users that are embedded into more complex HTML documents pretending to be other services, by fetching their logos from a third-party service like Clearbit or Google’s favicon database. RiskIQ found more than 700 unique domains running with LogoKit, targeting various services like SharePoint, Adobe Document Cloud, OneDrive, Office 365, and Cryptocurrency exchanges.

According to RiskIQ, the following legitimate services have been used by LogoKit actors:

  • me: Application Deployment Platform
  • com: Google Cloud Platform
  • app: Google Firebase
  • com: Google Firebase
  • googleapis.com: Google Cloud Storage
  • googleapis.com: Google Firebase Storage
  • amazonaws.com: Amazon S3 Object Storage
  • app: Google CodeSandbox
  • yandexcloud.net: Yandex Static Hosting
  • io: GitHub Static Page Hosting
  • com: DigitalOcean Object Storage
  • com: Oracle Object Storage

“LogoKit continues the trend of attacking with simplicity and small footprints. In executing only a few lines of customizable JavaScript and loading resources from trusted sources, such as Google Firebase, LogoKit increases its chances of success,” RiskIQ added.

Related Story: Five Phishing Baits You Need to Know

Google Delists Android App “Barcode Scanner”

WhisperGate malware campaign, Flagpro malware, MosaicLoader Malware, drinik

Security research firm Malwarebytes claimed that one of its forum users reported about a malicious app “Barcode Scanner” published by LavaBird LTD, which has over 10 million installations on the Google Play Store.

Several users, who downloaded the app, reported that unwanted ads were displayed on their default browser on Android devices without users’ consent. Malwarebytes stated that the app remained harmless for a long time and suddenly turned malicious after an update, which was released on December 4, 2020. It is suspected that the app developer intentionally added the malicious code (Android/Trojan.HiddenAds.AdQR) in the update that was not in previous versions of the app.

The app has been taken down from the Google Play Store after Malwarebytes reported the issue. However, the users who still have the app installed on their devices are vulnerable.  “Removing an app from the Google Play store does not necessarily mean it will be removed from affected mobile devices. Unless Google Play Protect removes it after the fact, it remains on the device. This is exactly what users are experiencing with Barcode Scanner,” Malwarebytes said.

Scanner Turns Malicious!

While it is unknown how long the Barcode Scanner app had been in the Google Play store as a legitimate app before it became malware, it’s suspected that it had been there for years, based on the high number of installs and user feedback.

“It is frightening that with one update an app can turn malicious while going under the radar of Google Play Protect. It is baffling to me that an app developer with a popular app would turn it into malware. Was this the scheme all along, to have an app lie dormant, waiting to strike after it reaches popularity? I guess we will never know,” Malwarebytes added.

Users are advised to remove the app manually if they are still using it, to avoid any suspicious activities.

Safer Internet Day 2021: Together for a Better Internet

February 9, every year, marks Safer Internet Day. A day that is meant to focus on creating a safer cyberspace. The Safer Internet Day came into existence in 2012 when the U.S. DHS and European Commission decided to focus on making the internet safer for a growing number of youngsters who were starting to get accustomed to a connected-virtual lifestyle through the internet.

Ever since then, several nations have joined the bandwagon of celebrating this day to commemorate internet safety and establish best safety practices. The theme this year is “Together for a better internet.”

While this day majorly focuses on internet safety for children and young people, the surge in the remote workforce due to COVID-19 has broadened, and now even includes adults.  While common threats like malware, phishing, and ransomware campaigns are still wreaking havoc on the digital landscape, more sophisticated forms of attacks are also cropping up, often exploiting people’s fears. We approached industry leaders to seek insight on the cybersecurity implications of these threat vectors, what CISOs must do to safeguard their companies and employees, and how to make the internet a safer space for children and adults alike.

 

1. Security Awareness Training Should be a Top Priority for CISOs

“Safer Internet Day is a great reminder of the ever-evolving threats we face online. Every photo we post, job update we share, and person or place we tag, reveals valuable information about our personal and professional lives. Today, hackers are taking advantage of this level of detail to craft effective social engineered attacks. For example, we are seeing people post on their public social media pages the names of their pets, children, families, and interests. Meanwhile, employees are revealing too much information in their out-of-office messages, like where and how long they will be gone. Hackers can use all of this to try to crack passwords or convince colleagues to wire money. The solution isn’t to stop using out-of-office messages or social media. Rather, it’s about being educated and knowing how those details about your personal and professional life can be used against you or your company.

Implementing security awareness training should be a top priority for CISOs today, as it’s vital to educate employees about the dangers of sharing too much online. However, training needs to evolve to keep up with the constantly changing threat landscape by using real-world examples to provide context, like impersonation and BEC scams. It’s critical that business leaders today understand the risks in order to maximize the strength of their security posture.”

 

 

2. Deepfakes will be the Bigger Concern

“This Safer Internet Day, reliability of information is the theme, and with ‘fake news’ entering popular lexicon as a symptom of the massive amount of misinformation available online, this year we explore how fakery — as well being used for simple mischief-making — can be part of highly-targeted attacks.

We see the potential for Deepfakes to become a feature of enterprise attacks, amplifying existing social engineering techniques by making them appear even more credible. Deepfake footage is already available on the Dark Web; it is not too much of a stretch for attackers to lift video and recordings of senior business leaders from employers’ social media channels, marketing collateral, or from individual employees’ own digital footprint, for example, and using their properties to generate deepfakes that act as a strategic follow-on to phishing attempts.

We anticipate threat actors creating deepfakes in which they build a deepfake persona of a colleague in a position of trust – for instance, an IT team member – to highly-targeted, unsuspecting employees over a series of videos calls to earn their trust, before requesting credentials and using this information to access systems. Many of us, after all, haven’t even met our colleagues in these pandemic-dominated times. In fact, we believe this technique may well already be in use in certain scenarios, though the nature of such a highly-targeted attack would make this something which an attacker would go to great lengths to disguise.”

 

3. Collectively Make the Internet Safer for Everyone

“The internet has long been an important means for most of the globe to operate on a day-to-day basis, and the recent pandemic has elevated it to an even more essential component of our daily lives. Safer Internet Day is a significant observance and serves as a call to action for organizations and consumers alike to make the global online network a more valuable and protected resource.

In light of recent data breaches and hacks, organizations have even more of an obligation to protect customer information. Consumer trust is drastically low regarding data privacy, with 79% of adults expressing concerns over how companies are using and collecting data. To truly make the internet a better place, enterprises must adopt crowdsourced cybersecurity as an integral component of security posture. By making strategic investments in a layered cybersecurity approach to protect consumers, who are ultimately the biggest victims when cyberattacks and data breaches occur, organizations can meet the challenges of a distributed workforce and protect sensitive data from evolving threats.

From a consumer standpoint, identity theft and data breaches have been rising at a rapid pace — but there are numerous ways to ensure online browsing and interactions are safeguarded. Parental controls can be installed to ensure young children aren’t viewing explicit content, and users can opt out of data collection wherever possible to keep sensitive information confidential. Additionally, using multiple strong passwords, implementing two-factor authentication across accounts, sending encrypted files, and installing spyware and anti-virus software on devices can provide protection against viruses and malicious threat actors. It takes a community of defenders to combat a community of adversaries, and when we all come together, we can collectively make the internet a safer environment for everyone.”

 

4. Safer internet day is perhaps more important than ever this year

“Safer Internet Day is perhaps more important than ever this year. In the last twelve months, the way we work or access education has changed beyond recognition. Organizations have opened up networks to accommodate a remote workforce. Students are using apps and services, typically the realm of the corporate world, to participate in virtual classes. Many of these cloud-based tools and services are accessed using personal devices that are unsecured or beyond the remit of the IT or security team.  This expanded attack service presents an attractive target for attackers who frequently use personal devices to not only steal data on the device itself, but also look to move laterally across networks and cause further harm.

Research by Tenable’s Security Response Team, examining details from 730 publicly disclosed data breaches in 2020, found that threat actors rely on unpatched vulnerabilities in their attacks. These ‘broken windows’ are primarily used to gain initial access into a target network. From there, attackers leverage serious vulnerabilities, like Zerologon, to elevate privileges, granting themselves the ability to gain access to domain controllers within the network.

Most of these attacks are avoidable with basic safety steps. Good security awareness and basic cyber hygiene prevents mistakes that can cause serious harm. In tandem, it is critical that users take responsibility for updating and securing their devices to close these broken windows.

With technology now an integral part of modern life we all have a part to play in securing the devices we use.”

Cybercriminals Attempt Poisoning Florida City’s Water Supply

cybercriminals, intruder, intrusion, Florida city, Tampa Bay, city water supply poisoned, water supply poisoned, water supply plant, industrial control systems, ICS, Oldsmar city

Attacks on industrial control systems (ICS) are not new. Earlier, a report from industrial cybersecurity firm Claroty suggested that around 70% of the ICS vulnerabilities discovered in the first half of 2020 could be exploited remotely. That said, the intrusion attempt in the city of Oldsmar’s water supply is “Dangerous Stuff,” as rightfully quoted by Sheriff Bob Gualtieri of Pinellas County, Florida.

How Cybercriminals Attempted Poisoning the Entire City

On the morning of February 5, around 8 a.m., an employee of Oldsmar city’s water treatment plant observed his cursor moving around the screen. It did not raise any eyebrows since his supervisor accessed his system remotely using TeamViewer software for urgent maintenance work and IT issues. The random cursor movement stopped in some time. However, nearly five hours later, the cursor started moving again and, this time, he could see someone remotely accessing the software, which controlled the chemicals used in treating the water before it is supplied to the entire city.

The employee saw the intruder changing the sodium hydroxide levels of the water supply from 100 parts per million to more than 11,100 parts per million. Sodium hydroxide is a chemical compound (also known as lye), which, if used in lower concentrations, regulates the acidity or – in a geeky language – the pH level of water, making it potable for domestic use and drinking. However, this compound needs to be controlled and regulated since its higher concentration can even damage human tissues permanently, within minutes.

This is probably what the intruders of Oldsmar city wanted. However, the alert employee quickly took control of the system and brought the sodium hydroxide level back to 100 parts per million. The entire episode lasted merely between 3-5 minutes, and as Sheriff Gualtieri informed, it did not cause any harm to the water supply. The water treatment plant has uninstalled TeamViewer since the attack.

Gualtieri also informed that the poisoned water would not have reached the city taps of 15,000+ residents and local businesses before 24 hours. And, in the meanwhile, the pH sensors of the water supply plant would have triggered the alarms, which have been specifically designed to detect and tackle such scenarios. Eric Seidel, Mayor of Oldsmar, said,

The protocols that we have in place, monitoring protocols, they work — that’s the good news. Even had they not caught them, there’s redundancies in the system that would have caught the change in the pH level.

Addressing the cyberattack, Senate Marco Rubio tweeted by saying, “This should be treated as a matter of national security.”

Considering the gravity of the attack, federal agencies have been asked to jointly investigate with the local law enforcement authorities and find the perpetrator. Since the plant’s OT systems were externally accessible, Gualteri added, “If you’re connected, you’re vulnerable.”

What Experts are Saying

Chris Risley, CEO at Bastille Networks exclusively told CISO MAG that The water treatment system hack is troublesome because this underscores how vulnerable cities are to critical infrastructure intrusion. There’s widespread recognition of the need to eliminate potential intrusions and attacks, but limited adoption and enforcement of security policies to combat bad actors.”  Risley further added that his “company’s research and discoveries related to MouseJackKeySniffer, and KeyJack validate the thesis that the IoT is already being rolled out to individuals and enterprises with wireless protocols that have not been through sufficient security vetting. As a result, he expects millions of devices to be vulnerable to currently undiscovered attacks.”

What’s Our Viewpoint

Agreeing with both Gualtieri and Risley, we think that OT systems are critical infrastructure. And hence, they should never be open on the internet or be accessible to any other external network. Remote access to these systems – through TeamViewer or any other software – should be avoided completely.

Lastly, humans have always been labeled as the “Weak links” in cybersecurity. However, in this case,  a human turned out to be a stronger link and averted potentially deadly consequences. This incident serves as a good example and highlights the importance of training for ICS cybersecurity. To have a look at the training programs designed to counter industrial cybersecurity threats, click here.

Note: Updated the Expert’s Quotes on February 10, 2021.

Related News:

70% of ICS Flaws Unveiled in First Half of 2020 Can be Exploited Remotely

OT-ISAC Virtual Summit Brings Together the Best Minds in APAC for OT/ICS Security

Operation SECRETO: Europol Busts International Cybercriminal Group

Facebook Indicts Two Developers for Scraping Users’ Data, Europol

Europol dismantled an organized cybercriminal group that defrauded the U.S. banks for €12 million (US$14.4 million). A cross-border operation dubbed “Operation SECRETO,” coordinated by Europol and led by the Spanish National Police (Policía Nacional), and the U.S. Secret Service, busted the group involved in fraud and money laundering operations.

The operation also involved police services from Austria, Denmark, Greece, the U.S. Department of Justice, and the U.S. Financial Crimes Enforcement Network (FinCEN). The officials arrested 37 suspects (2 in Austria, 11 in Greece, 23 in Spain, and 1 in the U.K.) and took over 87 bank accounts worth €1.3 million (US$1.57 million).

Details of Operation SECRETO

  • 105 suspects arrested
  • 88 house searches
  • 87 accounts with more than €1.3 million frozen
  • €406,000 (US$490,508) seized in cash
  • 14 high-end vehicles seized
  • 19 European arrest warrants executed

The cybercriminal group, formed of Greek nationals, established shell companies in the U.S. and opened bank accounts, and made fraudulent transactions to the U.S.-based accounts from different locations in the EU. They leveraged the debit and credit cards issued by U.S. banks for fraudulent transactions. Over 50 financial institutions in the U.S. became victims of these deceptive operations losing around $14.4 million.

“Retailers in on the scam, most of whom were in Spain, used the payment cards to finance the available credited amounts on the cards. To launder the stolen funds, they transferred them to different bank accounts, owned by members of the criminal network located in several EU countries,” Europol said.

Europol has been working with the international intelligence teams to fight against cybercriminals and their operations globally. Recently, Europol and the European Commission launched a new decryption platform to boost Europol’s encryption capabilities during criminal investigations. The innovative decryption platform, controlled by Europol’s European Cybercrime Centre (EC3), was created in collaboration with the European Commission’s Joint Research Centre. The platform allows the authorities to decrypt information that is obtained lawfully in criminal investigations.

German Police Seize $60 Mn of Bitcoin from a Scammer who Refuses to Share Password

Sardonic, BitMart

A strong password habit of a fraudster is keeping the German prosecutors at bay. According to a report, the German police have seized over 50 million euros (US$60 million) worth of Bitcoin from a scammer, who has been sentenced to jail for installing malware on other computer systems to mine cryptocurrency. However, the officials couldn’t unlock his crypto wallet as the attacker is not revealing the password.

Cryptocurrency like Bitcoin is stored in a crypto wallet (digital wallet) with secure encryption. A crypto wallet does not store your digital coins; however, it holds a decryption key, which allows the user to trade cryptocurrency online. This decryption key is a digital identity for users of the cryptocurrency market, and anyone who gets hold of this key can perform fraudulent transactions or steal crypto coins from the wallet.

What’s the password?

The scammer has not revealed the decryption key throughout his jail time and during the interrogation with the authorities. The police officials made multiple efforts to crack the wallet’s password but failed. “We asked him, but he didn’t say. Perhaps he doesn’t know,” said Sebastian Murer, a prosecutor in the Bavarian town of Kempten.

It seems that the culprit has taken the words “Never reveal your password to others” very seriously.

Cybercriminals often leverage Bitcoins to perform various fraudulent activities. Recently, Bitcoin rose to more than $12,000 in trading value, which is its highest level since August 2019. According to the “2019 Cryptocurrency Anti-Money Laundering (AML)” report from blockchain security firm CipherTrace, cryptocurrency crimes across the world hit over $4.3 billion in 2019. Cybercriminals robbed over $125 million in Ethereum, Bitcoin, and other digital currencies from different cryptocurrency exchanges in 2019.

Related Story:

How to Safeguard Your Cryptocurrency Wallet from Digital Exploits