ATT&CKReferencesPalo Alto Howling Scorpius DEC 2024

Palo Alto Howling Scorpius DEC 2024

Zemah, Y. (2024, December 2). Threat Assessment: Howling Scorpius (Akira Ransomware). Retrieved January 8, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareMegazord

Megazord can terminate a list of specified services and processes.

T1059.003
Windows Command Shell
MalwareMegazord

Megazord can execute multiple commands post infection via `cmd.exe`.

T1083
File and Directory Discovery
MalwareMegazord

Megazord can ignore specified directories for encryption.

T1083
File and Directory Discovery
MalwareAkira _v2

Akira _v2 can target specific files and folders for encryption.

T1486
Data Encrypted for Impact
MalwareMegazord

Megazord can encrypt files on targeted Windows hosts leaving them with a ".powerranges" file extension.

T1486
Data Encrypted for Impact
MalwareAkira _v2

The Akira _v2 encryptor targets the `/vmfs/volumes/` path by default and can use the rust-crypto 0.2.36 library crate for the encryption processes.

T1489
Service Stop
MalwareAkira _v2

Akira _v2 can stop running virtual machines.

T1489
Service Stop
MalwareMegazord

Megazord has the ability to terminate a list of services and processes.

T1654
Log Enumeration
MalwareMegazord

Megazord has the ability to print the trace, debug, error, info, and warning logs.

T1654
Log Enumeration
MalwareAkira _v2

Akira _v2 can enumerate the trace, debug, error, info, and warning logs on targeted systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.