Megazord

S1191

Malware.View on attack.mitre.org

About this malware

Megazord is a Rust-based variant of Akira ransomware that has been in use since at least August 2023 to target Windows environments. Megazord has been attributed to the Akira group based on overlapping infrastructure though is possibly not exclusive to the group.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1057
Process Discovery

Megazord can terminate a list of specified services and processes.

T1059.003
Windows Command Shell

Megazord can execute multiple commands post infection via `cmd.exe`.

T1083
File and Directory Discovery

Megazord can ignore specified directories for encryption.

T1486
Data Encrypted for Impact

Megazord can encrypt files on targeted Windows hosts leaving them with a ".powerranges" file extension.

T1489
Service Stop

Megazord has the ability to terminate a list of services and processes.

T1654
Log Enumeration

Megazord has the ability to print the trace, debug, error, info, and warning logs.

Groups that use it1

Campaigns0

None recorded.

References3

  1. CISA Akira Ransomware APR 2024 Open source
    CISA et al. (2024, April 18). #StopRansomware: Akira Ransomware. Retrieved December 10, 2024.
  2. Cisco Akira Ransomware OCT 2024 Open source
    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.
  3. Palo Alto Howling Scorpius DEC 2024 Open source
    Zemah, Y. (2024, December 2). Threat Assessment: Howling Scorpius (Akira Ransomware). Retrieved January 8, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.