The National Cyber Security Centre Finland announced a surge in Akira ransomware attacks.
Threat actors used Akira malware in six out of the seven ransomware attacks reported in December 2023.
The attackers used VPNs that lacked multi-factor authentication.
They exploited CVE-2023-20269 on Cisco ASA or FTD devices and obtained initial access through brute force attack.
To increase pressure, hackers not only encrypt the target`s data, but also search and delete backup copies.
Security researchers disclosed the CVE-2023-20269 flaw in September 2023.
Cisco released patches one month later, so System Admins could apply them.
According to RedPacket Security, since the beginning of 2024, Akira announced infecting with ransomware ten other companies.
If you suffered a ransomware attack, we advise you to report the incident to law enforcement officials in your country.
That would only encourage the attackers to perpetuate their Ransomware-as-a-Service business model.
If you liked this article, follow us on LinkedIn, Twitter, Facebook, and Youtube, for more cybersecurity news and topics.
This Cyber News was published on heimdalsecurity.com. Publication date: Thu, 18 Jan 2024 22:43:05 +0000