Cyber Security News

Akira Ransomware Attacking Windows Server via RDP & Evades EDR Using Webcam

A sophisticated ransomware group called Akira has been responsible for approximately 15% of cybersecurity incidents in 2024.

The threat actor has deployed novel techniques to bypass security defenses, most notably by exploiting unsecured webcams to circumvent Endpoint Detection and Response (EDR) tools when deploying ransomware across corporate networks.

This innovative attack vector demonstrates the evolving tactics of cybercriminals who continuously adapt to overcome security measures deployed by organizations.

In a recent incident, S-RM’s team responded to an Akira ransomware attack where the threat actors initially followed their typical playbook.

After compromising the victim’s network through an externally facing remote access solution, they deployed AnyDesk.exe to maintain persistent access before exfiltrating sensitive data.

The attackers then moved laterally through the network using Remote Desktop Protocol (RDP), which allowed them to blend in with legitimate system administrator activities, making detection more challenging for security teams.

The attackers attempted to deploy their ransomware payload by uploading a password-protected zip file named ‘win.zip’ containing the malicious executable ‘win.exe’ to a Windows server.

However, this initial attempt was prevented when the organization’s EDR solution identified and automatically quarantined the suspicious file before it could be extracted and executed. This detection prompted the threat actors to pivot their approach rather than abandon the operation.

Following the failed deployment attempt, the attackers leveraged results from a previously conducted internal network scan that had identified Internet of Things (IoT) devices on the victim’s network, including webcams and a fingerprint scanner.

S-RM’s team researchers noted that these devices presented an opportunity for the attackers to bypass traditional security controls and continue their malicious campaign.

Webcam Exploitation Technique

The threat actors identified a vulnerable webcam as an ideal pivot point for several technical reasons.

The device had critical security vulnerabilities including remote shell capabilities, ran a lightweight Linux operating system compatible with command execution similar to standard Linux devices, and crucially, lacked any EDR protection due to its limited storage capacity.

Akira ransomware IoT attack chain (Source – S-RM)

After compromising the webcam, the attackers used it to generate malicious Server Message Block (SMB) traffic directed at the targeted Windows server.

This traffic went undetected by the organization’s security monitoring systems, allowing the threat actors to successfully encrypt files across the victim’s network.

The SMB protocol, while less efficient than other methods, proved effective when deployed from devices incompatible with security monitoring tools.

The ransomware binary used in this attack was identified with the SHA-1 hash ac9952bcfcecab for the Linux variant, while the Windows variant had a hash of 3920f3c6368651.

Security experts recommend implementing network segmentation for IoT devices, performing regular internal network audits, maintaining strict patch management practices for all connected devices, changing default passwords on IoT equipment, and powering off such devices when not in use to mitigate this emerging threat vector.

Are you from SOC/DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Start Now for Free.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago