216.73.217.22

Unmasking Akira: The ransomware tactics you can't afford to ignore

· Published 22/09/2025 08:04 · Modified 22/09/2025 19:42

Export JSON

Essential information

Published
22/09/2025 08:04
Modified
22/09/2025 19:42
Tags
2025-09-22 CVE-2023-20269 CVE-2023-27532 CVE-2024-40711 CVE-2024-40766 akira backup destruction credential-theft data exfiltration double-extortion encryption ransomware
Related entities
1 intrusion sets (apt), 16 techniques (mitre), 1 malware, 5 others

Description

The group has been targeting UK businesses since 2023, primarily affecting retail, finance, manufacturing, and medical sectors. Their tactics include exploiting SSL VPNs, using double extortion, and focusing on financial gain. Key observations from 2023-2025 include initial access through VPN exploitation, discovery tools like Netscan and Advanced Port Scanner, privilege escalation via Veeam vulnerabilities, lateral movement through RDP and SSH, and exfiltration using tools like WinSCP and FileZilla. targets backup systems, encrypts virtual disks and physical devices, and publishes stolen data on a Tor-based website. The group's activities show similarities to the Conti cybercrime organization, indicating possible links between them.