ATT&CKReferencesCisco Akira Ransomware OCT 2024

Cisco Akira Ransomware OCT 2024

Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software3

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
GroupAkira

Akira has used RDP for lateral movement.

T1027.001
Binary Padding
GroupAkira

Akira has used binary padding to obfuscate payloads.

T1036.005
Match Legitimate Resource Name or Location
GroupAkira

Akira has used legitimate names and locations for files to evade defenses.

T1059.001
PowerShell
GroupAkira

Akira has used PowerShell scripts for credential harvesting and privilege escalation.

T1078
Valid Accounts
GroupAkira

Akira uses valid account information to remotely access victim networks, such as VPN credentials.

T1083
File and Directory Discovery
MalwareAkira _v2

Akira _v2 can target specific files and folders for encryption.

T1083
File and Directory Discovery
MalwareAkira

Akira examines files prior to encryption to determine if they meet requirements for encryption and can be encrypted by the ransomware. These checks are performed through native Windows functions such as GetFileAttributesW.

T1480
Execution Guardrails
MalwareAkira _v2

Akira _v2 will fail to execute if the targeted `/vmfs/volumes/` path does not exist or is not defined.

T1486
Data Encrypted for Impact
MalwareMegazord

Megazord can encrypt files on targeted Windows hosts leaving them with a ".powerranges" file extension.

T1486
Data Encrypted for Impact
MalwareAkira _v2

The Akira _v2 encryptor targets the `/vmfs/volumes/` path by default and can use the rust-crypto 0.2.36 library crate for the encryption processes.

T1486
Data Encrypted for Impact
MalwareAkira

Akira can encrypt victim filesystems for financial extortion purposes including through the use of the ChaCha20 and ChaCha8 stream ciphers.

T1489
Service Stop
MalwareAkira _v2

Akira _v2 can stop running virtual machines.

T1558
Steal or Forge Kerberos Tickets
GroupAkira

Akira have used scripts to dump Kerberos authentication credentials.

T1654
Log Enumeration
MalwareAkira _v2

Akira _v2 can enumerate the trace, debug, error, info, and warning logs on targeted systems.

T1685
Disable or Modify Tools
GroupAkira

Akira has disabled or modified security tools for defense evasion.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.