ATT&CKReferencesKersten Akira 2023

Kersten Akira 2023

Max Kersten & Alexandre Mundo. (2023, November 29). Akira Ransomware. Retrieved April 4, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
MalwareAkira

Akira will leverage COM objects accessed through WMI during execution to evade detection.

T1057
Process Discovery
MalwareAkira

Akira verifies the deletion of volume shadow copies by checking for the existence of the process ID related to the process created to delete these items.

T1059.001
PowerShell
MalwareAkira

Akira will execute PowerShell commands to delete system volume shadow copies.

T1059.003
Windows Command Shell
MalwareAkira

Akira executes from the Windows command line and can take various arguments for execution.

T1082
System Information Discovery
MalwareAkira

Akira uses the GetSystemInfo Windows function to determine the number of processors on a victim machine.

T1083
File and Directory Discovery
MalwareAkira

Akira examines files prior to encryption to determine if they meet requirements for encryption and can be encrypted by the ransomware. These checks are performed through native Windows functions such as GetFileAttributesW.

T1106
Native API
MalwareAkira

Akira executes native Windows functions such as GetFileAttributesW and `GetSystemInfo`.

T1135
Network Share Discovery
MalwareAkira

Akira can identify remote file shares for encryption.

T1486
Data Encrypted for Impact
MalwareAkira

Akira can encrypt victim filesystems for financial extortion purposes including through the use of the ChaCha20 and ChaCha8 stream ciphers.

T1490
Inhibit System Recovery
MalwareAkira

Akira will delete system volume shadow copies via PowerShell commands.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.