Ransomware gang encrypted network from a webcam to bypass EDR
ID: 126489ad-e5ec-5e19-9c1d-9b8e0953ca27
STIX ID: report--126489ad-e5ec-5e19-9c1d-9b8e0953ca27
Feed Name: Bleeping Computer
### Executive summary: The Akira ransomware gang leveraged an unsecured Linux-based webcam to run a Linux encryptor that mounted SMB shares and encrypted files across a victim's network, effectively bypassing Windows EDR after their Windows payloads were quarantined; initial access involved exposed remote access, AnyDesk deployment, RDP lateral movement, and data theft. The case highlights IoT devices as overlooked attack vectors, the need to isolate and patch IoT/edge devices, and that EDR alone is insufficient to protect against cross-platform ransomware operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
