logo

Akira Ransomware Devastates Airlines Using Legit Tools

ID: 2dcfe951-66ed-5024-9315-323cf8f82288

STIX ID: report--2dcfe951-66ed-5024-9315-323cf8f82288

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2024-07-12

Date Updated: 2026-04-19

Author: Kaaviya

...
...

In June 2024 the Akira ransomware operator (Storm-1567) compromised a Latin American airline by gaining SSH access, exploiting CVE-2023-27532 on a Veeam backup server to escalate access, exfiltrating sensitive data (WinSCP to 77.247.126.158) and deploying ransomware across the network; adversaries used legitimate tools (Remmina, AnyDesk, Impacket, NetScan) and LOLBAS for reconnaissance and persistence in a double‑extortion campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.