惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
L
LangChain Blog
博客园_首页
J
Java Code Geeks
博客园 - 【当耐特】
Microsoft Azure Blog
Microsoft Azure Blog
小众软件
小众软件
WordPress大学
WordPress大学
V
Visual Studio Blog
T
The Blog of Author Tim Ferriss
U
Unit 42
酷 壳 – CoolShell
酷 壳 – CoolShell
Recent Announcements
Recent Announcements
C
Check Point Blog
IT之家
IT之家
Engineering at Meta
Engineering at Meta
N
Netflix TechBlog - Medium
A
About on SuperTechFans
aimingoo的专栏
aimingoo的专栏
D
Docker
有赞技术团队
有赞技术团队
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
阮一峰的网络日志
阮一峰的网络日志
I
InfoQ

ThreatDown by Malwarebytes

This SonicWall bug is 2 years old. Akira ransomware is still exploiting it. | ThreatDown AI threat so great that security “takes precedence over everything except critical business operations”  | ThreatDown How Grok unknowingly powers cybercrime | ThreatDown 74% of organizations exposed to shadow AI | ThreatDown The guardrails problem just played out on both sides of the same incident | ThreatDown The AI era of cybercrime has arrived: The 2026 Cybercrime in the age of AI report | ThreatDown Prinz Eugen ransomware: a deep dive into a new Go-based encryptor - ThreatDown by Malwarebytes GachiLoader adopts AI skill lure - ThreatDown by Malwarebytes The Attacks Hiding in Your Identity Logs - ThreatDown by Malwarebytes The identity nobody is watching - ThreatDown by Malwarebytes Weaponizing autonomy: The rise of malicious AI agent skills Why identity-based threats are the new battleground for cybersecurity CastleRAT attack first to abuse Deno JavaScript runtime to evade enterprise security 100% malware detection at 1.7% CPU: how ThreatDown stops Mac info stealers Machine-scale cybercrime: The 2026 State of Malware report How to prevent a rootkit attack AI-orchestrated cyberattacks Tracking remote ransomware attacks at their source Inside EDR-Freeze: How ThreatDown stops the attack before it spreads
The anatomy of an Akira ransomware attack
Bill Cozens · 2026-01-18 · via ThreatDown by Malwarebytes
Superhero on Motorcycle Animation

Anything but science fiction: an analysis of a real life Akira ransomware attack.

Since we first observed it in April 2023, the Akira ransomware gang has made a big name for itself in a short time. With 244 confirmed attacks from April 2023 to March 2024, Akira has already become the eighth most prolific ransomware group since we began tracking all gangs in February 2022.

Akira made headlines in April after the Cybersecurity and Infrastructure Security Agency (CISA) FBI announced that the gang made $42 million from 250 attacks since March 2023, or an average of $3,500,000 a month. The CISA report also details Akira’s Tools, Tactics, and Procedures (TTPs).

Recently, a ThreatDown MDR client suffered an Akira ransomware attack. The incident involved sophisticated infiltration tactics, resulting in significant data encryption and operational disruption; however, the ThreatDown MDR team swiftly intervened to help the client recover from the attack. Let’s dive into the details.

Initial detection of Akira ransomware attack

The ThreatDown MDR team first received an alert indicating suspicious ransomware activity originating from the NTOSKRNL.EXE process. The alert highlighted that thousands of files were renamed with the .akira file extension, signaling a ransomware attack.

Timeline of events:

  • 05/31/2024, 9:37:29 AM – [Endpoint 1]: The first endpoint is encrypted with the .akira extension.
  • 05/31/2024, 9:48:21 AM – [Endpoint 2]: The second endpoint is encrypted with the .akira extension.
  • 05/31/2024, 10:25:04 AM – [Endpoint 3]: A third endpoint is encrypted with the .akira extension.

Infection analysis

Network connections: The NTOSKRNL.EXE processes on both endpoints showed evidence of communication with the domain controller (Endpoint 2) over port 445 (SMB). This suggested that the domain controller might have been distributing the ransomware, although concrete evidence was lacking due to the endpoint being offline.

Suspicious executable: On Endpoint 2, the team identified a suspicious executable located at C:\USERS\[REDACTED]\DOCUMENTS\WIN.EXE. This executable appeared to be the ransomware encryptor, deploying the malware to internal hosts over port 445 (SMB). The process graph indicated communication with 17 different endpoints.

Akira ransomware attack methodology

Tools and Techniques

  1. Cloudflare Tunnel:
    • Used to gain initial access to Endpoint 2.
    • Command: C:\Users\[REDACTED]\Documents\Cloudflare.exe tunnel run --token [REDACTED]
  2. Advanced IP Scanner:
    • Used to scan the network and identify targets.
    • Command: "C:\Users\[REDACTED]\AppData\Local\Temp\Advanced IP Scanner 2\advanced_ip_scanner.exe" /portable "C:/Users/[REDACTED]/Documents/" /lng en_us
  3. WIN.EXE:
    • Deployed ransomware to identified targets.
    • Command: "C:\Users\[REDACTED]\Documents\win.exe" -s=C:\Users\[REDACTED]\Documents\path2.txt -n=20 -remote

PowerShell activity

  • Suspicious PowerShell and cmd.exe activities had been previously excluded from monitoring by the customer, blinding the team to these activities.
  • Proxy execution of processes through a whitelisted PowerShell resulted in the following actions:
    • Dropping files to excluded directories.
    • Deleting shadow copies.
    • Logging users off remote hosts.
    • Querying remote desktop services.
    • Deleting legitimate admin users.

Screenshots of events

Akira Ransomware Encryption
Akira encryption
Akira Installing Cloudflare Tunnel
Akira installing Cloudflare Tunnel, used to access endpoint
Akira Deleting Legitimate Admins
Akira deleting legitimate admins, enumerating domain groups and creating illegitimate users
Advanced IP Scanner
Advanced IP Scanner used to scan the network, identify targets

Potential root cause of Akira attack

The initial vector for the attack involved using PowerShell to create a Cloudflare Tunnel.This tunnel facilitated the attackers’ remote access, followed by deploying Advanced IP Scanner to identify network targets. Subsequently, the ransomware from Akira was deployed from theWIN.EXE executable.

Remediation actions

The remediation process included:

  • Identifying compromised users and deactivating their accounts.
  • Identifying and deleting illegitimate admin users created by the threat actors.
  • Isolating impacted systems.
  • Identifying and isolating the host distributing the ransomware.
  • Rebuilding the list of infected machines and slowly reintroducing them back into the network.

Detecting ransomware attacks with ThreatDown MDR

By promptly isolating affected systems and revoking compromised accounts, the ThreatDown MDR team stopped the spread of Akira ransomware and initiated recovery procedures to restore normal operations.

Purpose-built for organizations with small (to non-existent) security teams that lack the resources to address threats like Akira ransomware, the ThreatDown Ultimate Bundle includes award-winning technologies and 24x7x365 expert-managed monitoring and response from the ThreatDown MDR team.

Talk to an MDR expert today.

Editor’s Note: This post was originally published in June 2024 and has been updated for accuracy and comprehensiveness.