HomeSecurityAkira ransomware: Linux version targets VMware ESXi servers

Akira ransomware: Linux version targets VMware ESXi servers

Akira ransomware uses a function to encrypt VMware ESXi virtual machines and double-cross companies worldwide.

See also: Hackers infect Linux SSH servers with Tsunami botnet malware

Akira ransomware

Akira is a software first released in March 2023 that targets Windows systems in various industries, including education, finance, real estate, construction, and consulting.

Threat actors steal data from compromised networks and encrypt files so they can extort businesses. The payments demanded are multi-million dollar, double-extorting the victims. This is also the case with other ransomware gangs targeting businesses.

The ransomware attack has affected over 30 victims in the United States since its inception. There have been two periods of intense attacks, one in late May and one today, as identified by ID Ransomware submissions.

Recently, malware analyst rivitna discovered the Linux version of Akira. He shared a sample of the new encryptor on VirusTotal last week.

In recent years, ransomware gangs have created specialized Linux cryptographers to encrypt VMware ESXi servers. This is because businesses use virtual machines for servers to better manage their devices and use their resources more efficiently.

By planning to install ESXi servers, there is a risk that a malicious actor can encrypt multiple servers running as virtual machines in a single ransomware encryption attack.

See also: Fake zero-day PoC exploits on GitHub spread Windows and Linux malware

Linux

However, Akira's encryptors do not include advanced features such as automatically shutting down virtual machines before encrypting files using the esxcli command, unlike other VMware ESXi encryptors.

  • -p –encryption_path (targeted file/folder paths)
  • -s –share_file (targeted network drive path)
  • – n –encryption_percent (percentage of encryption)
  • –fork (create a child process for encryption)

Cyble published a report on the Linux version of Akira. The analysts explain that the encryptor includes a public RSA encryption key and uses multiple algorithms , such as AES, CAMELLIA, IDEA-CB, and DES, to encrypt files.

The group recently announced a higher number of victims due to the expansion of Akira's targeting range, making the threat more serious for organizations around the world.

See also: Buhti ransomware: Uses leaked code for Windows, Linux

Unfortunately, more and more ransomware groups are adding support for Linux. They use available tools to do this, as it is an easy and almost undetectable way to increase their profits.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS