Threat Brief: Understanding Akira Ransomware
ID: 0c69fd41-4edd-5229-b477-cd0e4276bca5
STIX ID: report--0c69fd41-4edd-5229-b477-cd0e4276bca5
Feed Name: Qualys Blog
Akira is an active Ransomware-as-a-Service observed since March 2023 and linked to Conti affiliates; attackers use compromised credentials and public-facing exploits to gain access, perform AD/network reconnaissance, dump credentials, move laterally (RDP, PsExec), exfiltrate and leak data, delete backups/shadow copies, and encrypt files. The report includes a sample MD5, IoCs, MITRE ATT&CK mappings, command-line and behavioral indicators, and detection/hunting queries and EDR recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
