logo

Inside Akira Ransomware’s Rust Experiment

ID: 444c9943-b589-5f7b-8f9f-f79902173888

STIX ID: report--444c9943-b589-5f7b-8f9f-f79902173888

Feed Name: Check Point Research

Threat Score
78/100

Date Published: 2024-12-03

Date Updated: 2026-04-27

Author: benhe

...
...

This report presents an in-depth reverse-engineering analysis of a Rust-compiled Akira ransomware variant that targeted ESXi servers in early 2024, explaining how Rust idioms and aggressive inlining obscure control flow; it documents the program's CLI, thread-spawning model, encryption scheme (Curve25519 for asymmetric and SOSEMANUK for symmetric), VM shutdown behavior, and provides key IOCs including a sample SHA256, the VM termination command, and the .akiranew encrypted extension.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.