Akira ransomware uses a function to encrypt VMware ESXi virtual machines and double-cross companies worldwide.
See also: Hackers infect Linux SSH servers with Tsunami botnet malware

Akira is a software first released in March 2023 that targets Windows systems in various industries, including education, finance, real estate, construction, and consulting.
Threat actors steal data from compromised networks and encrypt files so they can extort businesses. The payments demanded are multi-million dollar, double-extorting the victims. This is also the case with other ransomware gangs targeting businesses.
The ransomware attack has affected over 30 victims in the United States since its inception. There have been two periods of intense attacks, one in late May and one today, as identified by ID Ransomware submissions.
Recently, malware analyst rivitna discovered the Linux version of Akira. He shared a sample of the new encryptor on VirusTotal last week.
In recent years, ransomware gangs have created specialized Linux cryptographers to encrypt VMware ESXi servers. This is because businesses use virtual machines for servers to better manage their devices and use their resources more efficiently.
By planning to install ESXi servers, there is a risk that a malicious actor can encrypt multiple servers running as virtual machines in a single ransomware encryption attack.
See also: Fake zero-day PoC exploits on GitHub spread Windows and Linux malware

However, Akira's encryptors do not include advanced features such as automatically shutting down virtual machines before encrypting files using the esxcli command, unlike other VMware ESXi encryptors.
- -p –encryption_path (targeted file/folder paths)
- -s –share_file (targeted network drive path)
- – n –encryption_percent (percentage of encryption)
- –fork (create a child process for encryption)
Cyble published a report on the Linux version of Akira. The analysts explain that the encryptor includes a public RSA encryption key and uses multiple algorithms , such as AES, CAMELLIA, IDEA-CB, and DES, to encrypt files.
The group recently announced a higher number of victims due to the expansion of Akira's targeting range, making the threat more serious for organizations around the world.
See also: Buhti ransomware: Uses leaked code for Windows, Linux
Unfortunately, more and more ransomware groups are adding support for Linux. They use available tools to do this, as it is an easy and almost undetectable way to increase their profits.
