Akira Ransomware Extends Reach to Linux Platform
ID: a4170f3c-ce2a-5b13-ab09-dd439f67d70c
STIX ID: report--a4170f3c-ce2a-5b13-ab09-dd439f67d70c
Feed Name: Cyble Blog
Cyble Research and Intelligence Labs reports that the Akira ransomware, previously focused on Windows, has expanded to include a 64-bit Linux ELF variant (SHA256: 1d3b5c650533d13c81e325972a912e3ff8776e36e18bca966dae50735f8ab296). The report provides technical analysis (command-line parameters, hardcoded RSA public key, AES/CAMELLIA/IDEA/DES routines), a comprehensive list of targeted file extensions, observed victims (~46 publicly disclosed plus 30 additional identified, largely in the United States), MITRE ATT&CK mappings, IOCs, and recommended defensive measures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
