Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
GroupAkira | Akira has used RDP for lateral movement. |
| T1027.001 Binary Padding |
GroupAkira | Akira has used binary padding to obfuscate payloads. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAkira | Akira has used legitimate names and locations for files to evade defenses. |
| T1059.001 PowerShell |
GroupAkira | Akira has used PowerShell scripts for credential harvesting and privilege escalation. |
| T1078 Valid Accounts |
GroupAkira | Akira uses valid account information to remotely access victim networks, such as VPN credentials. |
| T1083 File and Directory Discovery |
MalwareAkira _v2 | Akira _v2 can target specific files and folders for encryption. |
| T1083 File and Directory Discovery |
MalwareAkira | Akira examines files prior to encryption to determine if they meet requirements for encryption and can be encrypted by the ransomware. These checks are performed through native Windows functions such as |
| T1480 Execution Guardrails |
MalwareAkira _v2 | Akira _v2 will fail to execute if the targeted `/vmfs/volumes/` path does not exist or is not defined. |
| T1486 Data Encrypted for Impact |
MalwareMegazord | Megazord can encrypt files on targeted Windows hosts leaving them with a ".powerranges" file extension. |
| T1486 Data Encrypted for Impact |
MalwareAkira _v2 | The Akira _v2 encryptor targets the `/vmfs/volumes/` path by default and can use the rust-crypto 0.2.36 library crate for the encryption processes. |
| T1486 Data Encrypted for Impact |
MalwareAkira | Akira can encrypt victim filesystems for financial extortion purposes including through the use of the ChaCha20 and ChaCha8 stream ciphers. |
| T1489 Service Stop |
MalwareAkira _v2 | Akira _v2 can stop running virtual machines. |
| T1558 Steal or Forge Kerberos Tickets |
GroupAkira | Akira have used scripts to dump Kerberos authentication credentials. |
| T1654 Log Enumeration |
MalwareAkira _v2 | Akira _v2 can enumerate the trace, debug, error, info, and warning logs on targeted systems. |
| T1685 Disable or Modify Tools |
GroupAkira | Akira has disabled or modified security tools for defense evasion. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.