MSPs a top target for Akira and Lynx ransomware
ID: 8701ae1f-9cb6-5174-8a38-7afae1097529
STIX ID: report--8701ae1f-9cb6-5174-8a38-7afae1097529
Feed Name: TRU Security by Acronis
Acronis TRU analyzes Akira and Lynx ransomware families active in 2024–2025, detailing their RaaS operations, double-extortion behavior, exploitation of VPN/firewall CVEs and stolen credentials, technical encryption and evasion techniques (shadow copy deletion, process termination, printer ransom-note printing), and provides IoCs (SHA256 hashes and multiple .onion C2/leak site URLs); both target SMBs and sometimes MSPs, reuse leaked code elements, and present an ongoing high-risk threat to organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
