Akira ransomware continues to evolve
ID: 628958ce-f7cf-5f13-a2f5-643f03cb4817
STIX ID: report--628958ce-f7cf-5f13-a2f5-643f03cb4817
Feed Name: Cisco Talos
Akira ransomware continues to evolve and remains an active, high-impact threat: Cisco Talos documents the group's shift between Rust and C++ encryptors targeting Windows, Linux, and VMware ESXi, their exploitation of multiple high-severity CVEs (including SonicWall, VMware ESXi, Veeam, and Cisco ASA/FTD issues), documented IOCs and hashes, observed victimology (manufacturing and professional services), and recommended mitigations such as patching, MFA, EDR/XDR, SIEM monitoring, and secure ESXi configurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
