Inside Akira Ransomware’s Rust Experiment
ID: 444c9943-b589-5f7b-8f9f-f79902173888
STIX ID: report--444c9943-b589-5f7b-8f9f-f79902173888
Feed Name: Check Point Research
This report presents an in-depth reverse-engineering analysis of a Rust-compiled Akira ransomware variant that targeted ESXi servers in early 2024, explaining how Rust idioms and aggressive inlining obscure control flow; it documents the program's CLI, thread-spawning model, encryption scheme (Curve25519 for asymmetric and SOSEMANUK for symmetric), VM shutdown behavior, and provides key IOCs including a sample SHA256, the VM termination command, and the .akiranew encrypted extension.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
