Ako Ransomware Exploits Windows APIs to Target Your System
ID: 5acea608-6662-52b4-86a8-d4804b4de2e0
STIX ID: report--5acea608-6662-52b4-86a8-d4804b4de2e0
Feed Name: Cyber Press
Ako ransomware is a C++-based RaaS variant of MedusaLocker that surfaced in 2020; the report describes a multi-stage attack using RDP/email gateway exploits for initial access, ingress tool transfer and process injection for payload execution, lateral movement via PsExec and WMI, discovery via Windows API and network calls, and encryption of files with RSA and AES-256 after deleting volume shadow copies and disabling recovery mechanisms. The analysis outlines specific TTPs and recommends detection and prevention measures including endpoint behavior monitoring, command-line activity analysis for shadow copy deletion, privileged account hardening, and robust backup strategies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
