Akira Ransomware Gang Extorts $42 Million; Now Targets Linux Servers
ID: 0b763880-9695-5992-af34-5d7c55216c8f
STIX ID: report--0b763880-9695-5992-af34-5d7c55216c8f
Feed Name: The Hacker News
**Executive summary:** The report details the Akira ransomware group's global operations—extorting approximately $42 million from over 250 victims as of January 1, 2024—highlighting its shift from a C++ Windows locker to Rust-based variants that also target VMware ESXi, exploitation of known Cisco vulnerabilities, use of RDP/VPN/spear-phishing/valid credentials for initial access, credential dumping (Mimikatz, LaZagne), BYOVD techniques, data exfiltration tools, and hybrid ChaCha20+RSA encryption; it situates Akira within the broader ransomware ecosystem alongside LockBit and Agenda and notes the proliferation of low-cost ransomware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
