logo

CISA warns of Akira ransomware Linux encryptor targeting Nutanix VMs

ID: ef9f2b0e-01bc-5e1c-affb-f4f2bb42bf03

STIX ID: report--ef9f2b0e-01bc-5e1c-affb-f4f2bb42bf03

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-11-13

Date Updated: 2026-07-18

Author: Lawrence Abrams

...
...

Akira ransomware operators have been observed expanding their capabilities to encrypt Nutanix AHV virtual machine disk files (.qcow2), leveraging compromised credentials and known vulnerabilities (including SonicWall and Veeam CVEs) to gain access, delete backups, exfiltrate data rapidly, and maintain persistence; the advisory provides new IOCs, details on attacker TTPs (lateral movement, backup tampering, use of tunneling services for C2), and recommends patching, MFA, and offline backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.