CISA et al. (2024, April 18). #StopRansomware: Akira Ransomware. Retrieved December 10, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
MalwareAkira | Akira will execute PowerShell commands to delete system volume shadow copies. |
| T1083 File and Directory Discovery |
MalwareAkira _v2 | Akira _v2 can target specific files and folders for encryption. |
| T1486 Data Encrypted for Impact |
MalwareAkira | Akira can encrypt victim filesystems for financial extortion purposes including through the use of the ChaCha20 and ChaCha8 stream ciphers. |
| T1486 Data Encrypted for Impact |
MalwareMegazord | Megazord can encrypt files on targeted Windows hosts leaving them with a ".powerranges" file extension. |
| T1486 Data Encrypted for Impact |
GroupAkira | Akira encrypts files in victim environments as part of ransomware operations. |
| T1489 Service Stop |
MalwareAkira _v2 | Akira _v2 can stop running virtual machines. |
| T1490 Inhibit System Recovery |
MalwareAkira | Akira will delete system volume shadow copies via PowerShell commands. |
| T1543 Create or Modify System Process |
MalwareAkira _v2 | Akira _v2 can create a child process for encryption. |
| T1657 Financial Theft |
GroupAkira | Akira engages in double-extortion ransomware, exfiltrating files then encrypting them, in order to prompt victims to pay a ransom. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.