Secureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1078 Valid Accounts |
GroupAkira | Akira uses valid account information to remotely access victim networks, such as VPN credentials. |
| T1133 External Remote Services |
GroupAkira | Akira uses compromised VPN accounts for initial access to victim networks. |
| T1213.002 Sharepoint |
GroupAkira | Akira has accessed and downloaded information stored in SharePoint instances as part of data gathering and exfiltration activity. |
| T1219 Remote Access Tools |
GroupAkira | Akira uses legitimate utilities such as AnyDesk and PuTTy for maintaining remote access to victim environments. |
| T1531 Account Access Removal |
GroupAkira | Akira deletes administrator accounts in victim networks prior to encryption. |
| T1560.001 Archive via Utility |
GroupAkira | Akira uses utilities such as WinRAR to archive data prior to exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
GroupAkira | Akira will exfiltrate victim data using applications such as Rclone. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.