Researchers Observe Sub-One-Hour Ransomware Attacks
ID: 8a3e4056-c146-524e-89f1-66bac62877a1
STIX ID: report--8a3e4056-c146-524e-89f1-66bac62877a1
Feed Name: Infosecurity Magazine (News)
Halcyon warns that the Akira ransomware group—suspected to include former Conti actors—completes full attack lifecycles in under four hours (sometimes under one), exploiting vulnerabilities in internet-facing VPN and backup appliances (e.g., SonicWall, Veeam, Cisco), using credential theft and IABs, exfiltrating data prior to encryption in a double-extortion model, and leveraging living-off-the-land tools; the report notes up to $244M in suspected proceeds and recommends layered defenses, detection of data staging/exfiltration, hardened third-party access, tested recovery, and dedicated anti-ransomware solutions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
