Friday, May 23, 2025
Homecyber securityAkira Ransomware Exploiting Zero-day Flaws For Organization Network Access

Akira Ransomware Exploiting Zero-day Flaws For Organization Network Access

Published on

SIEM as a Service

Follow Us on Google News

The Akira ransomware group, which first appeared in March 2023, has been identified as a serious threat to data security. It encrypts data and demands a ransom for decryption, affecting both Windows and Linux devices.

The group has about 140 organizations as its target. The encryption binary of Akira, like that of many other ransomware, removes volume shadow copies, targets particular file extensions, and ignores files located in particular directories (such as those that include system files).

In particular, the United States of America, the United Kingdom of Great Britain and Northern Ireland, and Canada were among the nations from which the gang claimed several victims.

- Advertisement - Google News

Specifics of Akira’s Recent Operations

Three phases were identified in the attack, according to CERT Intrinsec’s investigation. In the initial stage, Akira affiliates get access to the network by using credentials that have been stolen or by making use of the CVE-2023-20269 vulnerability (affecting Cisco ASA and FTD).

This enables them to perform brute-force attacks on local passwords covertly. By setting up local and domain accounts or installing remote access tools, they create their persistence in the information system. 

Subsequently, affiliates use the Remote Desktop Protocol to travel laterally throughout the infrastructure, gather data, exfiltrate it using Filezilla or WinSCP, and then remove all traces of their activities to evade discovery.

The second phase lasts several days, during which affiliates stay stealthy. They could be analyzing technical data gathered from the information system or examining data that has been exfiltrated.

Attack path
Akira’s operation timeline

In the final stage, the attackers reappear to establish their final points of persistence, turn off security measures, attempt to destroy backups and erase volume shadow copies before executing their encryption code on the designated servers.

Investigations carried out during Akira operations reveal that affiliates will employ as many practical and legitimate techniques as possible, perhaps to ensure EDR solutions are bypassed.

Attackers attempted to remove Volume Shadow Copies using PowerShell commands and a management console connection to remove VEEAM backups.

“They finally encrypted equipments on the information system, using an Akira encryption binary,” researchers said.

Recommendation:

  • Install a backup solution and regularly test the restoration procedure.
  • Maintain a minimum of one backup version outside the information system.
  • Keep an eye on backup infrastructure access.
Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

EU Targets Stark Industries in Cyberattack Sanctions Crackdown

The European Union has escalated its response to Russia’s ongoing campaign of hybrid threats,...

Venice.ai’s Unrestricted Access Sparks Concerns Over AI-Driven Cyber Threats

Venice.ai has rapidly emerged as a disruptive force in the AI landscape, positioning itself...

GenAI Assistant DIANNA Uncovers New Obfuscated Malware

Deep Instinct’s GenAI-powered assistant, DIANNA, has identified a sophisticated new malware strain dubbed BypassERWDirectSyscallShellcodeLoader. This...

Hackers Expose 184 Million User Passwords via Open Directory

A major cybersecurity incident has come to light after researcher Jeremiah Fowler discovered a...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

EU Targets Stark Industries in Cyberattack Sanctions Crackdown

The European Union has escalated its response to Russia’s ongoing campaign of hybrid threats,...

Venice.ai’s Unrestricted Access Sparks Concerns Over AI-Driven Cyber Threats

Venice.ai has rapidly emerged as a disruptive force in the AI landscape, positioning itself...

GenAI Assistant DIANNA Uncovers New Obfuscated Malware

Deep Instinct’s GenAI-powered assistant, DIANNA, has identified a sophisticated new malware strain dubbed BypassERWDirectSyscallShellcodeLoader. This...