Special Features

Malware Month

Akira: Perhaps the next big thing in ransomware, says Tidal threat intelligence chief

Scott Small tells us gang's 'intent and capability' should get the attention of CSOs


Interview It might not be as big a name as BlackCat or LockBit, but the Akira ransomware is every bit as dangerous, says one cybersecurity researcher – and it's poised to make a big impact. 

Scott Small, director of cyber threat intelligence at Tidal Cyber, said that most of what Akira is doing is pretty routine for a cyber-crime gang. Regardless, Small warns not to underestimate the crew, who he said is "very much a skilled group." 

While much of what it does is exploit well-known vulnerabilities, some of Akira's tactics are less common in the ransomware world, which makes it easier to spot and remediate if you know what you're looking for. For example, Akira relies on FTP to exfiltrate files, Small said, noting FTP isn't that common a tool for ransomware groups.

"Core cyber-hygiene mitigations can have a dramatic impact on reducing your risk against these attacks," Small said in an interview you can watch above. "But it does demonstrate again the creativity and the persistence of a lot of these groups."

It's also important to know that even if you run a modest-sized organization you may not be small enough to avoid Akira. "Adversaries may go after the low hanging vulnerable fruit and ancillary organizations and use that access to pivot into those primary target environments," Small said.

In other words, almost anyone and everyone is a target these days. So get those security updates installed as soon as is practically possible, but don't stop there - watch the rest of our interview above. ®

Send us news
3 Comments

Ransomware batters critical industries, but takedowns hint at relief

Whether attack slowdown continues downward trend is the million dollar question that security researchers can't answer

RansomHub hits 210 victims in just 6 months

The ransomware gang recruits high-profile affiliates from LockBit and ALPHV

Brain Cipher claims attack on Olympic venue, promises 300 GB data leak

French police reckon financial system targeted during Summer Games

RansomHub-linked EDR-killing malware spotted in the wild

Also: Your external-facing NetSuite sites need a review; five popular malware varieties for Q2, and more

Cicada ransomware may be a BlackCat/ALPHV rebrand and upgrade

Researchers find many similarities, and nasty new customizations such as embedded compromised user credentials

Feds bust minor league Radar/Dispossessor ransomware gang

The takedown may be small but any ransomware gang sent to the shops is good news in our book

Enzo Biochem ordered to cough up $4.5 million over lousy security that led to ransomware disaster

Three state attorneys general probed the company and found plenty to chastise

US accuses man of being 'elite' ransomware pioneer they've hunted for years

Authorities allege 'J.P. Morgan' practiced ‘extreme operational and online security’

US sues Georgia Tech over alleged cybersecurity failings as a Pentagon contractor

Rap sheet spells out major no-nos after disgruntled staff blow whistle

Alleged Karakut ransomware scumbag charged in US

Plus: Microsoft issues workaround for dual-boot crashes; ARRL cops to ransom payment, and more

Tired of airport security queues? SQL inject yourself into the cockpit, claim researchers

Infosec hounds say they spotted vulnerability during routine travel in the US

Ransomware groups are better at web app security than you, says researcher

Could we please start taking this seriously?