HomeSecurityAkira ransomware spreads to Nutanix AHV

Akira ransomware spreads to Nutanix AHV

The Cybersecurity and Infrastructure Security Agency (CISA), along with the FBI and several international partners, has issued a new warning to organizations about the growing threat posed by the Akira ransomware group to critical infrastructure. The latest update indicates that the Akira ransomware group has expanded its capabilities beyond VMware ESXi and Hyper-V and is now targeting Nutanix AHV virtual machines.

See also: Akira ransomware compromises MFA-protected SonicWall VPN accounts

Akira ransomware
Akira ransomware spreads to Nutanix AHV

While Akira initially focused on small and medium-sized businesses in North America, Europe, and Australia, the group has increasingly turned its attention to large enterprises, with recent incidents infecting organizations in the manufacturing, IT, healthcare, financial services, and agriculture sectors. As of the end of September 2025, Akira ransomware has generated an estimated $244.17 million in ransomware revenue, CISA noted.

To gain initial access, the Akira threat actor exploited poorly secured virtual private network (VPN) services without multi-factor authentication (MFA), using known common vulnerabilities and exposures in products such as Cisco and SonicWall. Techniques used include password spraying techniques, in addition to spearphishing, abuse of valid credentials, and techniques that leverage externally accessible services such as Remote Desktop Protocol.

In some cases, it also gained access via the Secure Shell (SSH) protocol by exploiting the IP address of a router. After infiltrating through a targeted router, it exploited publicly available vulnerabilities, such as those found in the Veeam Backup and Replication component of unpatched Veeam backup servers, the alert noted. Malicious commands, including Visual Basic (VB) scripts, were executed.

Akira threat actors used the nltest /dclist: and nltest/DOMAIN_TRUSTS for network and domain discovery. Additionally, to evade detection, they abused remote access tools such as AnyDesk and LogMeIn to maintain persistence and integrate with administrator activity. They used Impacket to execute the remote wmiexec.py and also uninstalled endpoint detection and response (EDR) systems. The threat actors also created new user accounts and added them to the Administrators group to establish a foothold in the environment.

See also: A simple text file led to Akira Ransomware attacks

Akira ransomware spreads to Nutanix AHV
Akira ransomware spreads to Nutanix AHV

For command and control (C2) communications, it previously used two ransomware variants against different architecture systems during a breach attempt – the Windows-specific “Megazord” ransomware and the Akira ESXi encryptor, Akira_v2. However, Megazord has likely fallen into disuse by 2024. According to the new update, tunneling utilities, such as Ngrok, are used to initiate encrypted sessions that bypass perimeter monitoring.

It also uses PowerShell and the Windows Management Instrumentation (WMIC) command line to disable services and execute malicious scripts. It uses tools like FileZilla and WinRAR to collect data and WinSCP and RClone to extract data. And after extracting data, it used a dual extortion model, including encrypting systems and threatening to leak sensitive information. The alert noted that Akira threat actors were able to extract data in just over two hours from initial access.

Akira malicious actors use the ChaCha20 stream cipher with an RSA public key system for fast and secure key exchange. While previously encrypted files appeared with the .akira or .powerranges extension, the new Akira_v2 variant also uses .akiranew or .aki. To prevent system recovery and hinder forensic analysis, the Akira cryptographer (w.exe) used PowerShell commands to delete Volume Shadow Copy Service (VSS) copies on Windows systems.

According to the new update, a ransom note named fn.txt or akira_readme.txt appears in both the root directory and the user directory. A threat that thrives on the blind spots of businesses. Of the blind spots, remote access is at the top of the list, followed by the update.

See also: Hitachi Vantara: Problems due to Akira ransomware attack

Akira ransomware spreads to Nutanix AHV
Akira ransomware spreads to Nutanix AHV

Proactive threat hunting, strict privilege management, and practiced recovery plans are also crucial. Businesses should also practice full-scale ransomware scenarios. Thinking like an attacker is now a key skill, and closing gaps before they are exploited is what stands between disruption and survival.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS