Max Kersten & Alexandre Mundo. (2023, November 29). Akira Ransomware. Retrieved April 4, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
MalwareAkira | Akira will leverage COM objects accessed through WMI during execution to evade detection. |
| T1057 Process Discovery |
MalwareAkira | Akira verifies the deletion of volume shadow copies by checking for the existence of the process ID related to the process created to delete these items. |
| T1059.001 PowerShell |
MalwareAkira | Akira will execute PowerShell commands to delete system volume shadow copies. |
| T1059.003 Windows Command Shell |
MalwareAkira | Akira executes from the Windows command line and can take various arguments for execution. |
| T1082 System Information Discovery |
MalwareAkira | Akira uses the |
| T1083 File and Directory Discovery |
MalwareAkira | Akira examines files prior to encryption to determine if they meet requirements for encryption and can be encrypted by the ransomware. These checks are performed through native Windows functions such as |
| T1106 Native API |
MalwareAkira | Akira executes native Windows functions such as |
| T1135 Network Share Discovery |
MalwareAkira | Akira can identify remote file shares for encryption. |
| T1486 Data Encrypted for Impact |
MalwareAkira | Akira can encrypt victim filesystems for financial extortion purposes including through the use of the ChaCha20 and ChaCha8 stream ciphers. |
| T1490 Inhibit System Recovery |
MalwareAkira | Akira will delete system volume shadow copies via PowerShell commands. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.