Detecting Akira Ransomware Attack Using AhnLab EDR
ID: 44949cef-f8b7-5d7e-8c59-9e21dc7e00a9
STIX ID: report--44949cef-f8b7-5d7e-8c59-9e21dc7e00a9
Feed Name: ASEC
**Executive summary:** The report analyzes the Akira ransomware group (active since March 2023), detailing their use of stolen/weak VPN credentials and multiple publicly disclosed vulnerabilities for initial access, credential dumping (Mimikatz, Comsvc.dll, LaZagne, NTDS.dit), lateral movement (RDP, PsExec, Impacket), data collection/exfiltration (WinRAR, FTP, cloud storage, Rclone), and final encryption (.akira) with extortion via a TOR leak site; it also provides AhnLab EDR detection mappings and MITRE ATT&CK alignments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
