logo

Akira Ransomware Killchain

ID: 20aad251-f796-446f-8a1f-02ec3700475b

STIX ID: report--20aad251-f796-446f-8a1f-02ec3700475b

Threat Score

72/100

Uploaded: 2026-05-28

Created by: OpenCTI

TLP:GREEN
...
...
This diary-style forensic write-up reconstructs an Akira ransomware kill chain observed at a mid-sized organization using only perimeter SSLVPN syslog and Windows EVTX logs. The attacker used credential-stuffing against a local VPN account, performed discovery (nltest/net/whoami/AdFind-like tooling), executed Kerberoasting, moved laterally via RDP to obtain domain privileges, cleared logs and stopped defenses, deleted shadow copies, and encrypted data; the report includes concrete detection/hunting recommendations and ATT&CK mappings.