ZeroHour
The Recordpublished ()ingested

Akira ransomware gang made $42 million from 250 attacks since March 2023: FBI

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-3259
Unauthenticated Memory-Disclosure Flaw in Cisco ASA and FTD Web Services

CVE-2020-3259 is an information-disclosure vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software, caused by a buffer-tracking error when the device parses invalid URLs. An unauthenticated, remote attacker can trigger it by sending a crafted GET request to the web services interface, which allows retrieval of the device's memory contents and disclosure of confidential information. Only devices with specific AnyConnect and WebVPN configurations are affected, but those configurations are common on ASA/FTD firewalls deployed as enterprise edge and remote-access VPN gateways. Exploitation is confirmed in the wild: CISA added the bug to its Known Exploited Vulnerabilities catalog on 2024-02-15 with known ransomware use, and the Akira ransomware group (which the FBI says has extorted $42 million across roughly 250 attacks since March 2023) is actively exploiting it, with LockBit also scanning for vulnerable Cisco ASA devices. EPSS assigns a 71.8% probability of exploitation within 30 days, and no public proof-of-concept code is known.

Do: Upgrade affected ASA and FTD devices to the fixed releases listed in Cisco's security advisory for CVE-2020-3259; if patching is delayed, disable or restrict the web services interface (WebVPN/AnyConnect) to trusted source networks. Per the CISA KEV required action, apply vendor mitigations or discontinue use where mitigations are unavailable. Prioritize internet-facing VPN gateways and hunt for exploitation indicators (anomalous GET requests to the web services interface) given active Akira and LockBit targeting.

7.572% KEV ransomware
  • Cisco Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software
mass~100,000+ internet-exposed ASA/FTD devices with the web services (WebVPN/AnyConnect) interface enabled
CVE-2023-20269
Unauthenticated Brute-Force VPN Access in Cisco ASA and Firepower Threat Defense

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an authentication weakness (CWE-288) that allows an unauthenticated, remote attacker to conduct brute-force attacks against the SSL VPN login interface to guess valid username and password combinations, and to establish a clientless SSL VPN session as an unauthorized user under certain configurations. The attack is triggered simply by sending repeated or crafted authentication attempts to an internet-facing remote-access VPN endpoint, and vendor guidance centers on the group-lock and vpn-simultaneous-logins settings. A successful attempt gives the attacker VPN access, typically allowing them to reach the internal network as a legitimate user, which makes the flaw a common foothold for follow-on attacks including ransomware. Any organization operating a Cisco ASA or FTD with remote-access/clientless SSL VPN exposed to the internet is affected. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-13 with known ransomware use, and EPSS assigns it a 25.6% probability of exploitation within 30 days (98th percentile).

Do: Apply the mitigations in the Cisco advisory: configure group-lock and per-user vpn-simultaneous-logins restrictions as directed, and update ASA/FTD to the fixed releases listed there; if the device is end-of-support/unsupported, discontinue or isolate it. Prioritize internet-facing VPN concentrators given the KEV listing and known ransomware use, and review VPN logs for unusual failed-login bursts and unexpected clientless SSL VPN sessions.

9.125% KEV ransomware
  • Cisco Adaptive Security Appliance (ASA)
  • Cisco Firepower Threat Defense (FTD)
masshundreds of thousands of internet-exposed ASA/FTD VPN devices
Full article535 words · extracted from therecord.media · click to collapse

The Akira ransomware gang has attacked more than 250 organizations over the last year and continues to impact a “wide range of businesses and critical infrastructure entities in North America, Europe, and Australia,” the FBI and European law enforcement agencies warned Thursday.

Officials from the FBI, Cybersecurity and Infrastructure Security Agency (CISA), Europol’s European Cybercrime Centre (EC3), and the Netherlands’ National Cyber Security Centre (NCSC-NL) published an advisory on Thursday about the group, which has earned about $42 million in ransoms since emerging in March 2023. 

After initially targeting Windows systems, Akira has deployed a Linux variant targeting VMware ESXi virtual machines that are used widely across many large businesses and organizations. 

The gang has been seen using both variants of its ransomware within an attack on a single organization, marking “a shift from recently reported Akira ransomware activity.”

Akira ransomware actors have used known Cisco vulnerabilities like CVE-2020-3259 and CVE-2023-20269 to breach organizations through virtual private network (VPN) services that did not have multifactor authentication enabled. 

The hackers also use spearphishing campaigns and other tools to breach organizations. Once inside, they typically disable security software as a way to avoid detection while moving laterally. 

According to the law enforcement agencies, the ransomware gang uses several different tools to exfiltrate data including FileZilla, WinRAR, AnyDesk and more. 

“Akira threat actors do not leave an initial ransom demand or payment instructions on compromised networks, and do not relay this information until contacted by the victim,” the agencies said

“Ransom payments are paid in Bitcoin to cryptocurrency wallet addresses provided by the threat actors. To further apply pressure, Akira threat actors threaten to publish exfiltrated data on the Tor network, and in some instances have called victimized companies, according to FBI reporting.”

The group’s large number of attacks shortly after emerging led experts to believe it is made up of experienced ransomware actors.

The ransomware gang has claimed a steady stream of incidents in 2024, including anattack on prominent cloud hosting services provider Tietoevry

The group has taken credit for other attacks on Stanford University, the largest switching and terminal railroad in the U.S., the government of Nassau Bay in Texas; Bluefield University; a state-owned bank in South Africa; major foreign exchange broker London Capital Group; and Yamaha’s Canadian music division.

Researchers at cybersecurity firm Arctic Wolf analyzed cryptocurrency transactions and found that in at least three separate transactions, Akira threat actors sent the full amount of their ransom payment to addresses affiliated with the now-defunct ransomware gang Conti.

Akira ransomware users paid over $600,000 in total to Conti-affiliated addresses. Two of the Conti-affiliated wallets were associated with Conti's leadership team, with one receiving payments from multiple ransomware families, Arctic Wolf said.

A decryptor for the ransomware was released last July but the group has been able to close loopholes in its code and continue attacks. 

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/akira-ransomware-attacked-hundreds-millions