Akira Ransomware: Lightning-Fast Data Exfiltration in 2-ish Hours
ID: b2482d6e-684b-5858-aa09-f182b3491098
STIX ID: report--b2482d6e-684b-5858-aa09-f182b3491098
Feed Name: Dark Reading
Date Published: 2024-07-11
Date Updated: 2026-05-05
Author: Tara Seals, Managing Editor, News, Dark Reading
BlackBerry Threat Research analyzed a June Akira ransomware incident in which Storm-1567 exploited an unpatched Veeam backup server (likely CVE-2023-27532) to quickly exfiltrate sensitive data (133 minutes) using living-off-the-land tools (WinSCP, Advanced IP Scanner, AnyDesk) and returned the next day to deploy Akira ransomware network-wide; the report warns of rapidly shrinking time-to-exfiltration and recommends zero-trust, diligent patching, and basic network hygiene such as port restrictions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
