Friday, August 28, 2026

Online or Offline , That's Is the Question

How Akira Attacks NetworksInitial Access: Hackers target remote connections. They exploit unpatched VPN appliances or use stolen login credentials.Lateral Movement: Once inside, they disable security tools and move across the network.Data Theft: They steal sensitive files before encrypting local systems.Virtual Machine Target: They attack hypervisors like VMware ESXi to lock down entire virtual machine environments at once.Extortion: They demand large cryptocurrency payments. If the victim refuses to pay, Akira publishes the stolen data on a dark web leak site. https://en.wikipedia.org/wiki/Akira_(ransomware) Akira is ransomware which emerged in March 2023.[1] It targeted over 250 entities including: US energy firm BHI Energy,[2] Nissan Australia,[3][4] the Finnish IT services provider Tietoevry,[5][6][7][8] and Stanford University.[9][10] The group has also claimed responsibility for a ransomware attack on the Toronto Zoo, though the zoo has not linked the incident to any particular threat actor.[11] Akira is offered as ransomware-as-a-service.[12] Akira is estimated to have earned up to $42 million from its inception in March 2023, until April 2024.[13] Methods Akira primarily targets Cisco VPN products as an attack vector to breach networks, especially those without multi-factor authentication enabled.[14][15] The group uses publicly available or natively installed tools and techniques for lateral movement. There are both Windows and Linux variants of Akira ransomware. Akira uses double-extortion ransomware techniques, in which data is exfiltrated from the environment before it is encrypted with threats to publish this data if a ransom is not paid.[16] A report by Halcyon released in April 2026 claimed the group could move rapidly and encrypt a victim organization's data within an hour after initial compromise, and that the group takes steps to ensure it can deliver recovered data to victims after ransom payments are made.[17] Akira v2 Akira v2 is written in Rust and is designed to locate files based on specific parameters, tailoring encryption to more specific file types.[18] These file types are often associated with database project files, optical media, Exchange mailbox databases, virtual hard disks, and other file types associated with virtualization and virtual machines. Key Generation Akira used CryptGenRandom to generate a symmetric key, which itself was then encrypted by the combination of a ChaCha20 stream cipher and an RSA-4096 public key, which was appended to the end of encrypted files.[1] The threat actors possessed the private key, preventing decryption without paying a ransom. Akira ransomware has both a Windows and Linux version, though the Windows version uses the Windows CryptoAPI library while the Linux variant uses the Crypto++ library to encrypt devices when the ransomware is deployed. Decryptor In June of 2023, Avast released a decryptor for the Akira ransomware, likely exploiting the partial file encryption approach used at the time to crack the encryption without obtaining any keys.[19] The decryptor does not work natively on Linux systems, and if needed it is recommended to use a WINE layer to run the decryptor on a Linux machine. References "#StopRansomware: Akira Ransomware | CISA". www.cisa.gov. April 18, 2024. "BHI-notice". www.documentcloud.org. Retrieved 2025-03-08. Paganini, Pierluigi (December 22, 2023). "Akira ransomware gang claims the theft of sensitive data from Nissan Australia". Security Affairs. "Nissan Australia cyberattack claimed by Akira ransomware gang". BleepingComputer. Retrieved 2025-03-08. Paganini, Pierluigi (January 24, 2024). "Akira ransomware attack on Tietoevry disrupted the services of many Swedish organizations". Security Affairs. "Akira ransomware hits cloud service Tietoevry; numerous Swedish customers affected". therecord.media. Tietoevry.com. "Restoration work progressing at Tietoevry". www.tietoevry.com. Retrieved 2025-03-08. Tietoevry.com. "UPDATE: Ransomware attack in Swedish data center". www.tietoevry.com. Retrieved 2025-03-08. Staff, S. C. (January 22, 2024). "Akira ransomware group's changing tactics: What you need to know". SC Media. "Stanford says data from 27,000 people leaked in September ran "Toronto Zoo shares update on last year's ransomware attack". BleepingComputer. Retrieved 2025-03-08. "Akira ransomware compromised at least 63 victims since March, report says". therecord.media. Paganini, Pierluigi (April 21, 2024). "Akira ransomware received $42M in ransom payments from over 250 victims". Security Affairs. Sead Fadilpašić (October 14, 2024). "Veeam vulnerability exploited to deploy malware via compromised VPN credentials". TechRadar. "#StopRansomware: Akira Ransomware | CISA". www.cisa.gov. 2024-04-18. Retrieved 2025-03-08. "Akira, GOLD SAHARA, PUNK SPIDER, Group G1024 | MITRE ATT&CK®". attack.mitre.org. Retrieved 2025-03-08. djohnson (2026-04-02). "Akira ransomware group can achieve initial access to data encryption in less than an hour". CyberScoop. Retrieved 2026-04-03. Brown, Jade. "Akira Ransomware: A Shifting Force in the RaaS Domain". Bitdefender Blog. Retrieved 2025-03-08. Team, Threat Research (2023-06-29). "Decrypted: Akira Ransomware". Avast Threat Labs. Retrieved 2025-03-07. See also Conti (ransomware) https://www.globenewswire.com/news-release/2026/08/24/3349950/0/en/paylogix-llc-data-breach-ademi-llp-investigates-claims-for-damages.html Paylogix, LLC Data Breach: Ademi LLP Investigates Claims for Damages https://therecord.media/norway-cyberattack-ddos-government Daryna Antoniuk August 25th, 2026 Large DDoS attack knocks Norwegian public services offline A handful of Norwegian government services have been disrupted for more than a day after a large-scale cyberattack targeted the infrastructure used to operate them, authorities said. The Norwegian Digitalisation Agency, known as Digdir, said the distributed denial-of-service (DDoS) attack began Monday and targeted the infrastructure of its IT partner, Vivicta. Such attacks flood servers with traffic in an attempt to make them unavailable to legitimate users. Digdir said it was working with Vivicta to stabilize the affected systems, with some services gradually coming back online. The attack has continued for around 30 hours at varying levels of intensity and, as of Tuesday morning, was still affecting some services, according to Digdir's status page. The incident disrupted 10 digital services used for verifying people's identities, logging into public services, exchanging data and documents between government agencies and businesses, accessing public records, and managing employee access. Among the affected systems was ID-porten, a digital identification service that acts as a gateway to thousands of Norwegian government services. It allows people to verify their identity using services such as BankID and MinID and has more than 4.5 million users. The disruption also affected parts of Norway's health infrastructure because several health services rely on ID-porten for authentication. Authorities warned of possible problems accessing online pharmacies and Norway's electronic prescription system. It is the third DDoS incident to affect Digdir's services since June, according to Norwegian media. "What is special about this latest attack, which has now been ongoing for a day, is that it is two to three times larger than what we experienced last time," Digdir press officer Are Kvistad told Norwegian public broadcaster NRK. It was not immediately clear who was behind the attack or whether the recent incidents were connected or part of a broader campaign targeting Norway. https://therecord.media/university-of-texas-forced-to-take-systems-offline-cyberattack-san-antonio Jonathan Greig August 18th, 2026 University of Texas forced to take systems offline in San Antonio after cyberattack One of the largest universities in Texas is facing a wide range of disruptions following a cyberattack announced on Monday morning. The University of Texas at San Antonio, which serves 40,000 students across six campuses, said its IT team identified threat activity on its academic campus over the weekend and took some systems, including phones, offline in response. Classes for many students begin on Wednesday, and the disruptions threaten to snarl systems people use to sign up for courses and submit payments for services. Michael Schnabel, the organization’s chief technology officer, said in a statement that the threat activity was detected at the edge of the university’s network and was contained before it reached “core systems and University Technology Solutions.” The university did not respond to questions about what was impacted. “At this time, our ongoing investigation has found no evidence that university data was accessed or exfiltrated as a result of this activity,” Schnabel said. “With classes beginning this Wednesday, we recognize how important, reliable access to university systems and services is for our students, faculty and staff. Our teams are working with great care to ensure that our technology environment is both available and secure as we begin the new academic year.” In light of the outages, the school said the deadline for student payments was extended to Friday and several other changes were made to the wait lists for courses. Late on Monday, the university said it planned for all students and teachers to reset their passwords but in a Tuesday update, they warned that the password reset effort was experiencing delays. No hacking group has taken credit for the attack. Cybercriminals have repeatedly targeted universities at the beginning and end of school years in an effort to force organizations to pay exorbitant ransoms. In May, universities across the U.S. were forced to delay final exams following a damaging cyberattack on a critical education software provider. Other large state universities like the University of Oklahoma, Stanford and the University of Michigan faced ransomware attacks following holiday breaks. The University of Pennsylvania had its email system disrupted in October during a cybersecurity incident while Columbia and Harvard Universities both faced attack last year https://therecord.media/social-engineering-hackers-explicit-photos-fbi-alert Jonathan Greig August 12th, 2026 FBI: Hackers using social engineering to breach accounts and steal explicit content Hackers are breaking into the social media accounts of both adults and children to steal explicit content and sell it on criminal marketplaces, according to a new FBI alert released this week. In a notice on Monday, the bureau said threat actors are “using a variety of social engineering and cyber intrusion tactics to target specific individuals of interest — who may or may not be known to the actor — or general targets of opportunity.” The FBI added that the hackers are also posting personal information alongside the explicit content. Some cybercriminals break into accounts by repeatedly trying different passwords or PINs found on data leak sites and other sources. When victims are people they know, the hackers use different variations of their birthday or name. In other cases seen by FBI agents, hackers have contacted victims pretending to be social media company representatives claiming their accounts have been breached. They bombard victims with texts requesting password resets or with codes that allow the threat actors to reset the victim’s password themselves. The notice adds that some incidents involved cloned social media sites made to look like legitimate platforms. When login information is entered on the fake sites, it is sent to the cybercriminals. The FBI noted that after the stolen content is posted or sold, victims often “face re-victimization through harassment, sextortion, stalking or other targeted attacks, such as advertising stolen content on a victim's own social media page.” The notice comes months after the Justice Department charged several people for conducting similar attacks. A 27-year-old Illinois man pleaded guilty in February after the DOJ accused him of being behind a campaign of hacks involving the Snapchat accounts of about 600 women. Last year, the DOJ indicted a former University of Michigan assistant football coach for hacking into the student athlete databases of more than 100 colleges and universities and accessing the medical information of about 150,000 people — using the data to break into the social media accounts of female student athletes Digdir said the attackers had not gained access to sensitive information stored in the affected systems.