logo

MSPs a top target for Akira and Lynx ransomware

ID: 8701ae1f-9cb6-5174-8a38-7afae1097529

STIX ID: report--8701ae1f-9cb6-5174-8a38-7afae1097529

Feed Name: TRU Security by Acronis

Threat Score
75/100

Date Published: 2025-08-04

Date Updated: 2026-07-25

...
...

Acronis TRU analyzes Akira and Lynx ransomware families active in 2024–2025, detailing their RaaS operations, double-extortion behavior, exploitation of VPN/firewall CVEs and stolen credentials, technical encryption and evasion techniques (shadow copy deletion, process termination, printer ransom-note printing), and provides IoCs (SHA256 hashes and multiple .onion C2/leak site URLs); both target SMBs and sometimes MSPs, reuse leaked code elements, and present an ongoing high-risk threat to organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.