Akira _v2

S1194

Malware.View on attack.mitre.org

About this malware

Akira _v2 is a Rust-based variant of Akira ransomware that has been in use since at least 2024. Akira _v2 is designed to target VMware ESXi servers and includes a new command-line argument set and other expanded capabilities.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1083
File and Directory Discovery

Akira _v2 can target specific files and folders for encryption.

T1480
Execution Guardrails

Akira _v2 will fail to execute if the targeted `/vmfs/volumes/` path does not exist or is not defined.

T1486
Data Encrypted for Impact

The Akira _v2 encryptor targets the `/vmfs/volumes/` path by default and can use the rust-crypto 0.2.36 library crate for the encryption processes.

T1489
Service Stop

Akira _v2 can stop running virtual machines.

T1543
Create or Modify System Process

Akira _v2 can create a child process for encryption.

T1654
Log Enumeration

Akira _v2 can enumerate the trace, debug, error, info, and warning logs on targeted systems.

Groups that use it1

Campaigns0

None recorded.

References3

  1. CISA Akira Ransomware APR 2024 Open source
    CISA et al. (2024, April 18). #StopRansomware: Akira Ransomware. Retrieved December 10, 2024.
  2. Cisco Akira Ransomware OCT 2024 Open source
    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.
  3. Palo Alto Howling Scorpius DEC 2024 Open source
    Zemah, Y. (2024, December 2). Threat Assessment: Howling Scorpius (Akira Ransomware). Retrieved January 8, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.