Saturday, April 12, 2025
HomeCVE/vulnerabilityAkira Ransomware Actively Exploiting Cisco Anyconnect Vulnerability

Akira Ransomware Actively Exploiting Cisco Anyconnect Vulnerability

Published on

SIEM as a Service

Follow Us on Google News

Threat actors exploit Cisco AnyConnect vulnerabilities to gain unauthorized access to networks, compromise sensitive information, and potentially execute malicious activities. 

Exploiting these vulnerabilities allows attackers to bypass security measures, leading to unauthorized control over network resources, potential disruptions to operations, cyber espionage, data theft, and ransomware deployment.

Cybersecurity analysts at Truesec recently discovered that Akira ransomware is actively exploiting the Cisco Anyconnect vulnerability.

- Advertisement - Google News

Truesec CSIRT found that Akira Ransomware has been actively exploiting the Cisco ASA and FTD flaw, which was tacked as “CVE-2020-3259,” which allows remote attackers to extract usernames and passwords from affected devices.

Akira Ransomware Exploiting CVE-2020-3259

Truesec’s analysis of eight recent Akira ransomware incidents links Cisco AnyConnect SSL VPN as the entry point. 

Six compromised devices ran vulnerable software, while data on the other two was inconclusive for CVE-2020-3259 susceptibility.

To exploit this vulnerability, the device must have AnyConnect SSL VPN enabled on the interface exposed to the attacker, typically the internet-facing firewall interface.

Document
Live Account Takeover Attack Simulation

How do Hackers Bypass 2FA?

Live attack simulation Webinar demonstrates various ways in which account takeover can happen and practices to protect your websites and APIs against ATO attacks.

Besides this, the following configuration should be in place:-

Cisco devices and the configurations enabling the vulnerability CVE-2020-3259 (Source – Truesec)
Software versions vulnerable to CVE-2020-3259 and fixed releases for Cisco ASA devices (Source – Truesec)
Software versions vulnerable to CVE-2020-3259 and fixed releases for Cisco FTD devices (Source – Truesec)

Positive Technologies discovered CVE-2020-3259 in May 2020 but faced US sanctions in April 2021 for alleged ties to Russian Intelligence. 

Akira was linked to the defunct Conti ransomware syndicate and may exploit the vulnerability. 

However, Truesec doesn’t directly tie Akira’s actions to Russian intelligence, as they warn of potential risks to Western defenses from shared offensive security research.

Recommendations

For organizations running Cisco Anyconnect, it’s crucial to track when your device was updated post-CVE-2020-3259 disclosure. 

Even if patched, the exploit indicators suggest potential prior exploitation. If the upgrade was 6 months old,, assume that the usernames/passwords used during that time were compromised. 

So, in that case, it’s strongly recommended to reset passwords and change any other device secrets immediately.

Here below, we have mentioned all the other recommendations provided by the security experts:-

  • Enable MFA everywhere possible and prioritize Client VPN connections.
  • Enforce password changes post-version upgrade, especially for untouched accounts.
  • Update secrets and pre-shared keys in device configurations post-version upgrade.
  • Patch to a secure version if not already completed.
  • Confirm logging is active across all systems.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.

Tushar Subhra
Tushar Subhra
Tushar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

Threat Actors Manipulate Search Results to Lure Users to Malicious Websites

Cybercriminals are increasingly exploiting search engine optimization (SEO) techniques and paid advertisements to manipulate...

Hackers Imitate Google Chrome Install Page on Google Play to Distribute Android Malware

Cybersecurity experts have unearthed an intricate cyber campaign that leverages deceptive websites posing as...

Dangling DNS Attack Allows Hackers to Take Over Organization’s Subdomain

Hackers are exploiting what's known as "Dangling DNS" records to take over corporate subdomains,...

HelloKitty Ransomware Returns, Launching Attacks on Windows, Linux, and ESXi Environments

Security researchers and cybersecurity experts have recently uncovered new variants of the notorious HelloKitty...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Dangling DNS Attack Allows Hackers to Take Over Organization’s Subdomain

Hackers are exploiting what's known as "Dangling DNS" records to take over corporate subdomains,...

Threat Actors Launch Active Attacks on Semiconductor Firms Using Zero-Day Exploits

Semiconductor companies, pivotal in the tech industry for their role in producing components integral...

Hackers Exploit Router Flaws in Ongoing Attacks on Enterprise Networks

Enterprises are facing heightened cyber threats as attackers increasingly target network infrastructure, particularly routers,...