CERT-In cautions internet users against ransomware 'Akira' attack

An Internet ransomware virus 'Akira' that steals vital personal information and encrypts data leading to extortion of money from people has been reported, cyber security agency said

Ransomware attack
Photo: Bloomberg
Press Trust of India New Delhi
3 min read Last Updated : Jul 23 2023 | 2:18 PM IST

An Internet ransomware virus 'Akira' that steals vital personal information and encrypts data leading to extortion of money from people has been reported in the cyberspace, the country's federal cyber security agency has said in a latest advisory.

This computer malware is targeting Windows and Linux-based systems, it said.

"A recently emerged ransomware operation dubbed Akira is reportedly active in cyberspace. This group first steals the information from victims, then encrypt data on their systems and conducts double extortion to force the victim into paying the ransom.

"In case the victim does not pay, they release their victim's data on their dark web blog," the Indian Computer Emergency Response Team (CERT-In) said in a latest advisory to Internet users.

The agency is the central technology arm to combat cyber attacks and guards the cyber space against phishing and hacking assaults and similar online attacks.

It said the ransomware group is "known to access victim environments via VPN (virtual private network) services, particularly where users have not enabled multi-factor authentication."

Ransomware is a computer malware that infects and blocks users from using their own data and system and they can get it back against a pay-off.

This ransomware group has also utilised tools such as AnyDesk, WinRAR, and PCHunter during intrusions, it said, adding these tools are often found in the victim's environment, and their misuse typically goes unnoticed.

Describing the technical intrusion of the virus, the advisory said 'Akira' deletes the Windows Shadow Volume Copies on the targeted device.

The ransomware subsequently encrypts files with a predefined set of extensions and a '.akira' extension is appended to each encrypted file's name during this encryption process, it said.

In the encryption phase, the ransomware terminates active Windows services using the Windows Restart Manager API. This step prevents any interference with the encryption process, the advisory stated.

The ransomware encrypts files found in various hard drive folders, excluding the ProgramData, Recycle Bin, Boot, System Volume Information, and Windows folders.

The CERT-In also advised Internet users to use basic online hygiene and protection protocols to keep safe from such virus attacks in the online space.

Ransomware infections primarily keep data as hostage, hence, it is recommended to maintain offline backups of critical data and ensure that these backups stay up-to-date to prevent data loss in the event of infection, it suggested.

Also, the advisory recommended that operating systems and applications should be kept updated regularly and "virtual patching" can be considered for protecting legacy systems and networks.

This measure hinders cyber criminals from gaining easy access to any system through vulnerabilities in outdated applications and software, it said.

Users should also enforce strong password policies and multi-factor authentication (MFA) and void applying updates/patches available in any unofficial channel among other such measures to counter cyber and ransomware attacks, it said.

(Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

Topics :ransomwareCyber Attack

First Published: Jul 23 2023 | 2:18 PM IST

Next Story