EXECUTIVE SUMMARY
COMMON
CYBER THREATS
IN SINGAPORE
Examples of Phishing Scams:
Prevalent cyber threats observed in Singapore’s
cyberspace² in 2016 were defacements, phishing,
ransomware, and compromised Command & Control
(C&C) Servers, the last being potential launch-pads
for other cyber-attacks, such as DDoS. A snapshot
of these common cyber threats is as follows:
Ransomware:
Defacements:
C&C Servers & DDoS:
Phishing:
It is one of the biggest
cybersecurity threats
to businesses and
individuals today. Some
reports noted that there
may be as many as 550
ransomware-related
attacks every day in
Singapore. However,
many cases may go
unreported. Some people
may decide to reformat
their affected computer,
and companies may
not want to report
it to protect their
corporate reputation.
CSA received 19 reports
of ransomware cases
from individuals and
SMEs in 2016. Cerber,
CryptoLocker and Locky
were among the types of
ransomware reported.
As ransomware attacks
grew in 2016, SingCERT
issued an advisory in May
2016 to warn the public
of such dangers and
provided precautionary
measures to be adopted.
Nearly 1,800 website
defacements were
detected in Singapore in
2016, with the majority
being websites of
SMEs from a range of
businesses such as
interior design and
manufacturing. The
perpetrators included
hacktivists keen to
promote a certain
ideology, and whose
attacks were observed
across other countries as
well. One in 10 defaced
websites was hosted on
servers running outdated
operating systems, which
may have resulted in
them being vulnerable
to such attacks.
More than 60 C&C
servers were detected.
It is not immediately
apparent who might
have set them up, what
they intended to do with
these servers, and if
any damage was done.
Whenever a new C&C
server is detected,
SingCERT will inform the
respective Web hosting
providers to rectify the
issue. Potentially, C&C
servers could be used
to control botnets – a
network of compromised
computers ¬– that in
turn could be mobilised
for DDoS attacks. The
thousands of IoT devices
marshalled for DDoS
attacks in the USA in
October 2016 may hint of
similar threats to come.
DDoS ransom threats
were also observed in
Singapore’s cyberspace,
believed to be carried out
by cyber criminal groups.
More than 2,500 phishing
URLs were detected in
2016, with the Banking
& Finance sector
appearing to be the most
spoofed (31 per cent of
all observed phishing
URLs). Among online
services, PayPal was
spoofed most often in
phishing campaigns. CSA
also observed that filehosting service providers
were popular targets
as hackers could easily
harvest user credentials
from there. Some
Government institutions
were also spoofed,
as attackers sought
personal data such
as passport numbers
that could be traded in
underground markets.
“Singapore cyberspace” refers to websites ending with the .SG domain or mention Singapore in its URL, IP addresses used in Singapore or Internet Service
Providers (ISP) that are located in Singapore.
2
6
Phishing Site
Phishing E-mail
KEEPING OUR
CYBERSPACE SAFE AND
TRUSTWORTHY TOGETHER
A conducive environment for monitoring,
early detection, and quick response to
cyber threats and attacks also requires
effort in these areas:
Raising Cyber Awareness
Developing Cybersecurity
Professionals
Regional and
International Exchanges
Our outreach programmes
and roadshows aim to promote
cyber-savviness among
businesses and individuals.
SingCERT has issued advisories
to educate the public on cyber
issues such as ransomware,
DDoS attacks and compromised
remote servers.
Singapore is also growing its
cybersecurity ecosystem, which
includes boosting the talent pool.
The Cyber Security Associates
and Technologists (CSAT)
programme, a joint initiative by
CSA and the Infocomm Media
Development Authority (IMDA),
was launched in 2016 to train and
upskill new and existing ICT and
engineering professionals for
cybersecurity roles.
Singapore has been actively
involved in the past year in
various international platforms
on cybersecurity, from multilateral
discussions on cyber norms to
bilateral co-operation and regional
capacity-building programmes.
7