logo

Anatomy of an Akira Ransomware Attack: When a Fake CAPTCHA Led to 42 Days of Compromise

ID: 3f3ae125-a472-5c39-b370-6842007c23e0

STIX ID: report--3f3ae125-a472-5c39-b370-6842007c23e0

Feed Name: Palo Alto Networks Unit 42

Threat Score
78/100

Date Published: 2025-11-19

Date Updated: 2026-04-28

Author: Jeremy Brown

...
...

Unit 42 responded to a 42-day compromise at a global data storage company in which Howling Scorpius (Akira ransomware operators) used a ClickFix fake CAPTCHA to deliver SectopRAT, gained privileged access, moved laterally via RDP/SSH/SMB, exfiltrated ~1 TB of data, deleted backup storage, and encrypted systems across three networks; Unit 42 deployed Cortex XSIAM to reconstruct the attack, negotiated with the actors to reduce the ransom, and provided remediation and strategic recommendations including segmentation, credential rotation (KRBTGT), improved detection, and hardened cloud/endpoint practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.