CISA warns of Akira ransomware Linux encryptor targeting Nutanix VMs
ID: ef9f2b0e-01bc-5e1c-affb-f4f2bb42bf03
STIX ID: report--ef9f2b0e-01bc-5e1c-affb-f4f2bb42bf03
Feed Name: Bleeping Computer
Akira ransomware operators have been observed expanding their capabilities to encrypt Nutanix AHV virtual machine disk files (.qcow2), leveraging compromised credentials and known vulnerabilities (including SonicWall and Veeam CVEs) to gain access, delete backups, exfiltrate data rapidly, and maintain persistence; the advisory provides new IOCs, details on attacker TTPs (lateral movement, backup tampering, use of tunneling services for C2), and recommends patching, MFA, and offline backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
