ATT&CKReferencesCISA Akira Ransomware APR 2024

CISA Akira Ransomware APR 2024

CISA et al. (2024, April 18). #StopRansomware: Akira Ransomware. Retrieved December 10, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software3

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1059.001
PowerShell
MalwareAkira

Akira will execute PowerShell commands to delete system volume shadow copies.

T1083
File and Directory Discovery
MalwareAkira _v2

Akira _v2 can target specific files and folders for encryption.

T1486
Data Encrypted for Impact
MalwareAkira

Akira can encrypt victim filesystems for financial extortion purposes including through the use of the ChaCha20 and ChaCha8 stream ciphers.

T1486
Data Encrypted for Impact
MalwareMegazord

Megazord can encrypt files on targeted Windows hosts leaving them with a ".powerranges" file extension.

T1486
Data Encrypted for Impact
GroupAkira

Akira encrypts files in victim environments as part of ransomware operations.

T1489
Service Stop
MalwareAkira _v2

Akira _v2 can stop running virtual machines.

T1490
Inhibit System Recovery
MalwareAkira

Akira will delete system volume shadow copies via PowerShell commands.

T1543
Create or Modify System Process
MalwareAkira _v2

Akira _v2 can create a child process for encryption.

T1657
Financial Theft
GroupAkira

Akira engages in double-extortion ransomware, exfiltrating files then encrypting them, in order to prompt victims to pay a ransom.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.