logo

Detecting Akira Ransomware Attack Using AhnLab EDR

ID: 44949cef-f8b7-5d7e-8c59-9e21dc7e00a9

STIX ID: report--44949cef-f8b7-5d7e-8c59-9e21dc7e00a9

Feed Name: ASEC

Threat Score
75/100

Date Published: 2025-02-09

Date Updated: 2026-04-26

Author: ATCP

...
...

**Executive summary:** The report analyzes the Akira ransomware group (active since March 2023), detailing their use of stolen/weak VPN credentials and multiple publicly disclosed vulnerabilities for initial access, credential dumping (Mimikatz, Comsvc.dll, LaZagne, NTDS.dit), lateral movement (RDP, PsExec, Impacket), data collection/exfiltration (WinRAR, FTP, cloud storage, Rclone), and final encryption (.akira) with extortion via a TOR leak site; it also provides AhnLab EDR detection mappings and MITRE ATT&CK alignments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.