Akira ransomware scum blocked victim's security tools – and broke their own encryptor

Summary

The Akira ransomware group has been observed disabling victim security tools as part of their attacks. In a peculiar twist, this tactic backfired on them, causing them to break their own encryptor and hindering their ability to encrypt files.

IFF Assessment

FOE

The observation that Akira ransomware is disabling security tools is bad news for defenders, as it highlights an evolving evasion technique.

Defender Context

Defenders should be aware that ransomware groups like Akira are actively seeking ways to bypass security software, which necessitates robust endpoint detection and response (EDR) capabilities and layered security approaches. The incident also shows that attackers' own modifications can sometimes lead to unexpected failures, which defenders can potentially exploit in their incident response.

Read Full Story →