Akira Ransomware Now Uses APT-Style Tactics to Breach Corporate Networks
ID: 137d609c-9817-5dd3-899f-3778a8564dc7
STIX ID: report--137d609c-9817-5dd3-899f-3778a8564dc7
Feed Name: securityonline.info
S-RM’s analysis details a sophisticated Akira ransomware intrusion against a multinational agriculture company: attackers gained access via an unpatched single-factor VPN and exploited VMware vCenter RCE (CVE-2021-21972) to implant a reverse shell, spun up a near-undetectable VM, extracted NTDS.dit and the SYSTEM hive to obtain credentials, moved laterally, exfiltrated data, and deployed ransomware (including via abuse of Veritas Backup Exec) — all within roughly six hours, with operations impacting small and medium-sized organizations across North America, Europe, and Australia.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
