logo

Akira Ransomware Now Uses APT-Style Tactics to Breach Corporate Networks

ID: 137d609c-9817-5dd3-899f-3778a8564dc7

STIX ID: report--137d609c-9817-5dd3-899f-3778a8564dc7

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2024-05-20

Date Updated: 2026-04-22

Author: do son

...
...

S-RM’s analysis details a sophisticated Akira ransomware intrusion against a multinational agriculture company: attackers gained access via an unpatched single-factor VPN and exploited VMware vCenter RCE (CVE-2021-21972) to implant a reverse shell, spun up a near-undetectable VM, extracted NTDS.dit and the SYSTEM hive to obtain credentials, moved laterally, exfiltrated data, and deployed ransomware (including via abuse of Veritas Backup Exec) — all within roughly six hours, with operations impacting small and medium-sized organizations across North America, Europe, and Australia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.