[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/ "High Profile Threats")
* [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/ "Ransomware")  
  [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)

# Threat Assessment: Howling Scorpius (Akira Ransomware)

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 15 min read  
Related Products  
[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/product-category/cortex/ "Cortex")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex Xpanse icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex Xpanse](https://unit42.paloaltonetworks.com/product-category/cortex-xpanse/ "Cortex Xpanse")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/product-category/cortex-xsiam/ "Cortex XSIAM")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Yoav Zemah](https://unit42.paloaltonetworks.com/author/yoav-zemah/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:December 2, 2024

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/)
  * [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/)
  * [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Akira ransomware](https://unit42.paloaltonetworks.com/tag/akira-ransomware/)
  * [Bring Your Own Driver](https://unit42.paloaltonetworks.com/tag/bring-your-own-driver/)
  * [CVE-2020-3259](https://unit42.paloaltonetworks.com/tag/cve-2020-3259/)
  * [CVE-2023-20269](https://unit42.paloaltonetworks.com/tag/cve-2023-20269/)
  * [Double extortion](https://unit42.paloaltonetworks.com/tag/double-extortion/)
  * [ESXi](https://unit42.paloaltonetworks.com/tag/esxi/)
  * [FTP](https://unit42.paloaltonetworks.com/tag/ftp/)
  * [Howling Scorpius](https://unit42.paloaltonetworks.com/tag/howling-scorpius/)
  * [Lazagne](https://unit42.paloaltonetworks.com/tag/lazagne/)
  * [Leak site](https://unit42.paloaltonetworks.com/tag/leak-site/)
  * [Linux](https://unit42.paloaltonetworks.com/tag/linux/)
  * [Megazord](https://unit42.paloaltonetworks.com/tag/megazord/)
  * [Mimikatz](https://unit42.paloaltonetworks.com/tag/mimikatz/)
  * [Remote desktop](https://unit42.paloaltonetworks.com/tag/remote-desktop/)
  * [Rust](https://unit42.paloaltonetworks.com/tag/rust/)
  * [Server Message Block](https://unit42.paloaltonetworks.com/tag/server-message-block/)
  * [Torrenting](https://unit42.paloaltonetworks.com/tag/torrenting/)
  * [Windows](https://unit42.paloaltonetworks.com/tag/windows/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/threat-assessment-howling-scorpius-akira-ransomware/?pdf=download&lg=en&_wpnonce=9455982592 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/threat-assessment-howling-scorpius-akira-ransomware/?pdf=print&lg=en&_wpnonce=9455982592 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](<mailto:?subject=Threat%20Assessment:%20Howling%20Scorpius%20(Akira%20Ransomware)&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-howling-scorpius-akira-ransomware%2F> "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-howling-scorpius-akira-ransomware%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](<https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-howling-scorpius-akira-ransomware%2F&title=Threat%20Assessment:%20Howling%20Scorpius%20(Akira%20Ransomware)> "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](<https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-howling-scorpius-akira-ransomware%2F&text=Threat%20Assessment:%20Howling%20Scorpius%20(Akira%20Ransomware)> "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-howling-scorpius-akira-ransomware%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](<https://mastodon.social/share?text=Threat%20Assessment:%20Howling%20Scorpius%20(Akira%20Ransomware)%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-howling-scorpius-akira-ransomware%2F> "Share in Mastodon")

## Executive Summary

Emerging in early 2023, the Howling Scorpius ransomware group is the entity behind the Akira ransomware-as-a-service (RaaS), which has consistently ranked in recent months among [the top five most active](https://unit42.paloaltonetworks.com/unit-42-ransomware-leak-site-data-analysis/) ransomware groups. Its double extortion strategy significantly amplifies the threat it poses. Unit 42 researchers have been monitoring the Howling Scorpius ransomware group over the past year.

Howling Scorpius targets small to medium-sized businesses in North America, Europe and Australia, across various sectors. Affected industries include education, consulting, government, manufacturing, telecommunications, technology and pharmaceuticals.

Our research reveals that Howling Scorpius maintains and operates encryptors for Windows and Linux operating systems. We identified variants specifically designed for ESXi hosts. In addition, our findings have shown that this group is actively upgrading and enhancing its tool set, thus posing a greater risk for organizations.

Palo Alto Networks customers are better protected against Akira ransomware from the Howling Scorpius ransomware group through the following products and services:

* [**Cortex XDR**](https://www.paloaltonetworks.com/cortex/cortex-xdr) and [**XSIAM**](https://docs-cortex.paloaltonetworks.com/p/XSIAM)
* [**Cloud-Delivered Security Services**](https://docs.paloaltonetworks.com/cdss) for the [**Next-Generation Firewall**](https://docs.paloaltonetworks.com/ngfw), such as [**Advanced WildFire**](https://docs.paloaltonetworks.com/wildfire)
* [**Cortex Xpanse**](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

The Unit 42 Incident Response team has responded to several Howling Scorpius ransomware incidents since the group first emerged in 2023. If you think you might have been compromised or have an urgent matter, contact the [**Unit 42 Incident Response team**](https://start.paloaltonetworks.com/contact-unit42.html).

| **Related Unit 42 Topics** | [**Cybercrime**](https://unit42.paloaltonetworks.com/category/cybercrime/), **[Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)** |
|----------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------|

## Howling Scorpius Overview

[First observed in March 2023 \[PDF\]](https://www.cisa.gov/sites/default/files/2024-04/aa24-109a-stopransomware-akira-ransomware_2.pdf), Akira is a RaaS group we track as Howling Scorpius. This group employs a double extortion strategy, exfiltrating critical data from a network before executing its encryption process. This double extortion tactic allows the group to leak stolen data even if victims recover their systems without paying, maximizing the pressure to comply.

Howling Scorpius operates a Tor-based leak site for Akira ransomware. The group uses the site to list victims and exfiltrate stolen data if they refuse to comply with ransom demands.

The Akira leak site has a retro-green look. Howling Scorpius also operates a separate Tor-based negotiation site, which victims can access using a dedicated password provided by the group. Figure 1 shows a screenshot of the Akira ransomware leak site.
![Screenshot of a computer screen displaying a message from a hacker group named "AKIRA" on a dark-themed interface with green text. The message warns the user about a cyber incident and provides instructions for mitigating damage, and mentions commands available in the interface.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-494478-137681-1.png) Figure 1. Screenshot of the Akira Ransomware leak site in a Tor browser, from November 2024.

The Akira ransomware leak site displays a text-based console with a list of commands. The leaks command returns a list of victims who did not pay and includes links to download .torrent files. Viewers can then use these .torrent files to download the released data for those victims who did not pay their ransom.

This console also includes a news command that lists all compromised companies that it says date back as far as April 2023. The site describes the news command as "upcoming data releases," and the results end with the most recent victims.

The group primarily targets small to medium-sized businesses across various regions and industries.

### Targeted Regions

While Howling Scorpius has targeted organizations globally since 2023, the U.S. has emerged as the most affected country, according to Akira leak site data. Figure 2 highlights the top 10 affected countries based on this leak site data from March 2023-October 2024.
![Bar chart showing the count of Akira ransomware incidents by country. The United States has the highest count at 231, followed by Canada with 26, and the United Kingdom with 19. Other countries shown include Germany, Australia, Brazil, Italy, Sweden, Switzerland, and Austria with counts ranging from 12 to 4. Palo Alto Networks and Unit 42 lockup logo.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-499458-137681-2.png) Figure 2. A column chart showing the countries impacted by Howling Scorpius from March 2023-October 2024.

### Targeted Industries

Akira leak site data shows the group has impacted several industries, including manufacturing, professional and legal services, wholesale, retail and construction. Figure 3 shows the top 10 industries affected by this ransomware from March 2023-October 2024.
![Bar chart showing the count of Akira ransomware incidents by industry. From highest to lowest: Manufacturing with 74, Financial \& Legal Services with 39, Construction with 37, Wholesale and Retail with 36, High Technology with 36, Education with 26. Agriculture with 17. Media and Entertainment with 15, Transportation and Logistics with 14 and Telecoms with 12.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-502673-137681-3.png) Figure 3. The distribution of the top 10 sectors affected by Howling Scorpius from March 2023-October 2024.

## Technical Analysis of the Akira Ransomware Attack Lifecycle

Below is a technical analysis of Howling Scorpius operations mapped to the different stages of a [cyberattack's lifecycle](https://www.paloaltonetworks.com/cyberpedia/how-to-break-the-cyber-attack-lifecycle).

### Initial Access

Howling Scorpius affiliates employ various methods to gain initial access to organizations. These include exploiting vulnerable virtual private network (VPN) services that lack multi-factor authentication (MFA) using [valid accounts](https://attack.mitre.org/techniques/T1078/), often purchased through initial access brokers on the dark web.

Affiliates also target [external-facing services](https://attack.mitre.org/techniques/T1133/) like Remote Desktop Protocol (RDP), and they conduct spear phishing campaigns.

Figure 4 shows an alert raised by Cortex XDR for an example of a remote service creation. This specific alert involves using a service component of [PsExec](https://learn.microsoft.com/en-us/sysinternals/downloads/psexec#introduction) named PSEXESVC.exe to run a process from a remote system.
![A screenshot from Cortex XDR displaying a service start notification by a remote host, using PSExec.exe from the C:\\WINDOWS directory, and statistics about its remote service activity listed under XDR Analytics BIOC.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-505702-137681-4.png) Figure 4. Cortex XDR alert for remote service creation from an uncommon source.

The security community has documented Howling Scorpius [exploiting vulnerabilities](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-109a) in Cisco products, such as [CVE-2020-3259](https://nvd.nist.gov/vuln/detail/CVE-2020-3259) and [CVE-2023-20269](https://nvd.nist.gov/vuln/detail/CVE-2023-20269).

### Credentials Access

#### Local Credential Access Techniques

Howling Scorpius affiliates employ various credential access techniques to extract credentials for privilege escalation. [Mimikatz](https://attack.mitre.org/software/S0002/) and [LaZagne](https://attack.mitre.org/software/S0349/) are their primary tools.

Affiliates also often create a [MiniDump of the LSASS process memory](https://attack.mitre.org/techniques/T1003/001/) leveraging comsvcs.dll. Figure 5 shows an example of Cortex XDR detecting an example of comsvcs.dll used for this type of memory dump.
![Alert icon with an "A" inside a pink triangle, indicating a security notification about a memory dump performed using comsvcs.dll on Lsass.exe, commonly associated with unauthorized access attempts. Below the icon is the file name "rundll32.exe" and a command line path for further technical details.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-508384-137681-5.png) Figure 5. Cortex XDR detection alert of comsvcs.dll MiniDump of LSASS.

#### Kereberoasting

[Howling Scorpius affiliates employ](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-109a) the [Kerberoasting](https://attack.mitre.org/techniques/T1558/003/) attack to achieve control over service accounts and exploit credentials stored in memory.

#### Extracting Credentials for Domain Control

The group's affiliates focus on extracting credentials from the [Active Directory](https://en.wikipedia.org/wiki/Active_Directory) database to pursue comprehensive domain control. They copy the [SYSTEM registry hive](https://attack.mitre.org/techniques/T1003/002/) and [NTDS.dit](https://attack.mitre.org/techniques/T1003/003/) file from the [domain controller](https://en.wikipedia.org/wiki/Domain_controller) (DC) to obtain a complete listing of user accounts and their corresponding domain password hashes.

#### Exploiting Compromised vCenter Instances

In cases where affiliates compromise a vCenter instance, they will perform the following activities:

* Shutting down the DC's virtual machine (VM)
* Copying the DC's [Virtual Machine Disk](https://en.wikipedia.org/wiki/VMDK) (VMDK) files to another VM they created beforehand
* Extracting the NTDT.dit and SYSTEM registry hive files (as reported by [Rewterz](https://www.rewterz.com/threat-advisory/akira-ransomware-exfiltrates-domain-controller-files-by-privilege-escalation))

### Persistence

Howling Scorpius affiliates created [new domain accounts](https://attack.mitre.org/versions/v14/techniques/T1136/002/) to establish persistence. These accounts give these affiliates another form of access that does not require them to deploy tools or malware on the targeted systems. In addition, [CISA reported \[PDF\]](https://www.cisa.gov/sites/default/files/2024-04/aa24-109a-stopransomware-akira-ransomware_2.pdf) that the affiliates created new administrative domain accounts named itadm.

### Discovery and Lateral Movement

Howling Scorpius affiliates' lateral movement within compromised networks primarily involves exploiting remote services such as [Remote Desktop Procol (RDP)](https://learn.microsoft.com/en-us/troubleshoot/windows-server/remote/understanding-remote-desktop-protocol) and [Server Message Block (SMB)](<https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/hh831795(v=ws.11)>). The group also employs remote service creation and [Windows Management Instrumentation (WMI)](https://learn.microsoft.com/en-us/windows/win32/wmisdk/wmi-start-page) to further its reach.

These affiliates use network scanning tools like [NetScan](https://www.softperfect.com/products/networkscanner/) and [Advanced IP Scanner](https://www.advanced-ip-scanner.com/) to map the network and identify potential critical assets in the targeted organization for lateral movement. They also execute PowerShell and [Windows Net Commands](https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/net-commands-on-operating-systems) to query Active Directory for information on additional users and administrators.

### Defense Evasion

#### Bring Your Own Driver

Howling Scorpius affiliates use tools that abuse the [Zemana antimalware driver](https://www.bleepingcomputer.com/news/security/terminator-antivirus-killer-is-a-vulnerable-windows-driver-in-disguise/) to terminate antimalware-related processes. Figure 6 below shows information from an alert raised in Cortex XDR for attempting to create the malicious Zemana driver.
![Screenshot displaying a security alert from the Cortex XDR Agent. The alert is categorized as 'Behavioral Threat Protection' and details a 'Malicious driver creation attempt.'](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-511224-137681-6.png) Figure 6. Cortex XDR alert for the attempt to use the Zemana antimalware driver.

#### Anti Virus Disablement

Affiliates have also tried to disable Windows Defender Real-Time Protection using PowerShell, and they tried to uninstall the EDR agents installed on infected systems.

#### Bring Your Own VM

Affiliates sometimes create their own VMs. Within these VMs, they disable security tools. They then mount the [hypervisor](https://en.wikipedia.org/wiki/Hypervisor) host's storage drives onto the VM, shutting down any processes using those files to unlock running VM files. After successfully mounting the drives and unlocking all targeted files, they execute the ransomware within the new VM (as reported by [CyberCX](https://cybercx.com.au/blog/akira-ransomware/)), bypassing the host's security tools.

### Exfiltration

Howling Scorpius affiliates usually exfiltrate data from compromised hosts using WinRAR and a combination of [WinSCP](https://winscp.net/eng/docs/introduction), [RClone](https://rclone.org/) and [FileZilla](https://filezilla-project.org/), through the [File Transfer Protocol (FTP)](https://en.wikipedia.org/wiki/File_Transfer_Protocol). Below is an example of a data exfiltration attempt we observed:  
"C:\\Program Files\\WinRAR\\WinRAR.exe" a -ep1 -scul -r0 -iext -imon1 -- . "\[REDACTED\]\\Company\\\[REDACTED\]" \[REDACTED\]\\Company\\HR "\[REDACTED\]\\Company\\Human Resources Management - HR"

|---|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 | "C:\\Program Files\\WinRAR\\WinRAR.exe" a -ep1 -scul -r0 -iext -imon1 -- . "\[REDACTED\]\\Company\\\[REDACTED\]" \[REDACTED\]\\Company\\HR "\[REDACTED\]\\Company\\Human Resources Management - HR" |

## Akira Ransomware Encryptors

This section details the different encryptors for Akira ransomware that Howling Scorpius uses for Windows and Linux operating systems.

### Ransom Note

Upon successful encryption, Akira ransomware encryptors create a ransom note named akira\_readme.txt that provides victims instructions for how to interact with the group. This file includes links to both the leak site and the negotiation site.

The file also contains a unique code that victims must enter on the negotiation site to facilitate communication with the attackers and potential ransom discussions. Figure 7 shows an example of the akira\_readme.txt file.
![Screenshot of a cyberattack ransom demand note displayed on a computer screen, featuring a block of text with various instructions and threats, including a link and an unique code for further actions. Two red boxes highlight the leak site address and then the negotiation site and the end user's unique code, with redactions as necessary.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-514059-137681-7.png) Figure 7. An example of the akira\_readme.txt file content.

### Windows Variant

#### Execution

Upon execution, the Windows variant of the Akira ransomware encryptor will attempt to delete shadow copies using the following PowerShell command:

* powershell.exe -Command "Get-WmiObject Win32\_Shadowcopy | Remove-WmiObject"

#### Command-Line Arguments

The Windows variant of the Akira ransomware encryptor uses the following command-line arguments:

* \-p\\--encryption\_path -- Contains the root directory of the encryption process
* \-s\\--share\_file -- Contains the targeted network drive path
* \-n\\--encryption\_percent -- Controls the amount of data to be encrypted within each file
* \--fork -- Creates a child process for the encryption process
* \-l -- Writes the list of drives into the log file
* \-localonly -- Prevents the encryption of remote drives
* \-e/--exclude -- Contains files to exclude from the encryption process

Figure 8 below shows the Windows encryptor for the Akira ransomware detected and prevented by Cortex XDR.
![Image showing a security alert notification for "Suspicious File Modification" in Cortex XDR. The alert includes a stylized icon of a shield with the Cortex logo in a triangle at the top, and identifiers below such as source: "XDR Agent" and module: "Anti-Ransomware Protection" related to a file named "akira.exe".](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-517638-137681-8.png) Figure 8. Windows encryptor for Akira ransomware detected by Cortex XDR.

#### Encryption

Akira ransomware's Windows variant uses a hybrid approach to encrypt data. It encrypts the content of the files using the [ChaCha20](https://en.wikipedia.org/wiki/ChaCha20-Poly1305) algorithm.

The threat then encrypts the ChaCha20 key using a hard-coded RSA public key. The encryptor supports full and partial encryption, controlled through the aforementioned command-line parameter.

[Avast published a decryptor](https://decoded.avast.io/threatresearch/decrypted-akira-ransomware/#how_to) in June 2023 exploiting a vulnerability in Akira's encryption scheme. However, [CyberCX](https://cybercx.com.au/blog/akira-ransomware/) found a sample in VirusTotal that revealed that Howling Scorpius had patched this vulnerability within three days of its public disclosure.

In February 2024, we identified [updates in the Howling Scorpius codebase](https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2024-02-27-IOCs-for-Akira-Ransomware.txt). These updates included implementing support for the [KCipher2](https://en.wikipedia.org/wiki/KCipher-2) algorithm alongside ChaCha20. Encrypted files would use the .akira extension.

The list of the targeted file extensions and excluded directories the Howling Scorpius Windows encryptor uses can be found in [Appendix A](#post-137681-_hbmx1kf754k6).

### The Megazord Variant

In August 2023, a new strain of ransomware called Megazord appeared. This strain, written in [Rust](https://www.rust-lang.org/), has a ransom note with content similar to that of Akira ransomware and points to the same negotiation site. This indicates Howling Scorpius is also the same group behind Megazord.

Besides being written in Rust, Megazord variants differ from Akira encryptors by the following characteristics:

* Using a different file extension for encrypted files -- .powerranges
* Using a different name for the ransom note -- powerranges.txt

In addition, Megazord encryptors execute several commands to terminate and stop a list of services and processes that could affect the encryption process. For the complete list of commands executed by Megazord encryptors, please view [Appendix B](#post-137681-_fxmdjsw2h5or).

The Megazord strain has a new layer of protection, requiring a password as an execution condition (defined by the --id command-line argument). Figure 9 demonstrates how Cortex XDR detects and prevents Megazord.
![Alert notification from Cortex XDR Agent stating 'Suspicious File Modification' with the description 'Suspicious file modification detected.' The anti-ransomware protection module identifies the file named 'megazord.exe' as suspicious. The image features a stylized warning icon with a Cortex logo on a shield inside a triangle above a circular symbol.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-520207-137681-9.png) Figure 9. Megazord encryptor detected by Cortex XDR.

#### Updated Version

While looking for additional Megazord encryptors, we came across two samples that were compiled in March 2024, which had two new command-line arguments affecting the execution flow of the encryptor. The command-line argument --proc allows the attackers to turn off the termination of processes and services, and the --dirs command-line argument allows the attackers to ignore blocklisted directories.

Figure 10 shows the updated help menu from a Megazord sample.
![Screenshot of a command-line interface tool named 'megazord' displaying its usage, options, and version number. The options include various settings like path starting, thread number, error logging, process percent, and directory skipping.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-523134-137681-10.png) Figure 10. Megazord variant help menu.

#### The Possibility of Different Operators Sharing the Megazord Ransomware

Another unique sample we found differs primarily by its ransom note. This new ransom note raises the possibility that Megazord might not be exclusive to Howling Scorpius, although we cannot confirm this yet.

The new ransom note contains distinct language and a different means of communicating via Telegram, which hints at the involvement of a different threat actor. Figure 11 shows the new ransom note.
![The image displays a text of a ransomware threat message stating that the sender has paralyzed the recipient's systems and offers two options: contacting authorities or resolving the problem privately. The message implies possession of the recipient's data and confidentiality unless contact is not established. Some of the information is redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-525727-137681-11.png) Figure 11. The new Megazord ransom note.

### Linux/ESXi Variant

Based on the internal strings and naming conventions we observed in the Linux/[ESXi](https://core.vmware.com/esxi) variants of Akira ransomware, we assess that these samples were initially designed to run on ESXi systems. Some samples we encountered executed [ESXCLI](https://docs.vmware.com/en/VMware-vSphere/8.0/esxcli-80-getting-started.pdf) commands, strengthening our assessment. Figure 12 shows an example of an internal string found in one of the Linux/ESXi variants.
![A screenshot of a line of code. A string in white and green characters on a black background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-528135-137681-12.png) Figure 12. An example of an internal string of Linux/ESXi samples.

#### Execution

In some of the Akira Linux variants we have encountered, attackers changed the syslog logs directory to /tmp. It's likely they did this to disable logging and disable the [Core Dump file](https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-63728E8B-810D-418B-B1AA-6A0A2F92AABE.html) using the following ESXCLI commands:

* /bin/sh -c 'esxcli system syslog config set --logdir=/tmp'
* /bin/sh -c 'esxcli system syslog reload'
* /bin/sh -c 'esxcli system coredump file set --unconfigure'

#### Command-Line Arguments

The Linux/ESXi variant of the Akira ransomware encryptor uses the following command-line arguments:

* \-p\\--encryption\_path -- Specifies the root directory of the encryption process
* \-s\\--share\_file -- Specifies the targeted network drive path
* \-n\\--encryption\_percent -- Controls the amount of data to be encrypted within each file
* \--fork -- Creates a child process for the encryption process

Figure 13 demonstrates the detection and prevention of the Linux/ESXi variant by Cortex XDR.
![Alert notification in Cortex XDR from WildFire Malware indicating a suspicious executable detected named "akira.elf". The alert includes an icon of Cortex logo on a shield inside a warning triangle and a magnifying glass symbol.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-530393-137681-13.png) Figure 13. Howling Scorpius Linux/ESXi encryptor detected by Cortex XDR.

#### Encryption

Akira ransomware's Linux/ESXi variant uses a hybrid encryption approach to lock data, the same as its Windows variant. The Linux/ESXi variant encrypts the symmetric key used to encrypt the content of the targeted files with an embedded RSA public key.

This variant uses several symmetric encryption algorithms for the targeted file encryption, such as [AES](https://en.wikipedia.org/wiki/Advanced_Encryption_Standard), [CAMELLIA](<https://en.wikipedia.org/wiki/Camellia_(cipher)>), [DES](https://en.wikipedia.org/wiki/Data_Encryption_Standard) and [IDEA](https://en.wikipedia.org/wiki/International_Data_Encryption_Algorithm). Like the Windows version, this variant supports full and partial encryption controlled through the aforementioned command-line parameters.

The list of targeted file extensions and excluded directories by Akira ransomware's Linux/ESXi encryptor can be found in [Appendix C](#post-137681-_ifjvlpe9zc6j).

#### Akira v2

In April 2024, CISA's[#StopRansomware efforts \[PDF\]](https://www.cisa.gov/sites/default/files/2024-04/aa24-109a-stopransomware-akira-ransomware_2.pdf) revealed a new variant of the Akira ransomware's Linux/ESXi encryptor called Akira\_v2. This Rust-based variant introduces a new command-line argument set and expanded capabilities.

Like Megazord, Akira\_v2 also adds a new layer of protection by requesting a password using the --id argument as a run condition. In addition, by using the --vmonly argument, Akira\_v2 adds the ability to encrypt VM files only.

Figure 14 shows the help menu unique to this variant.
![Screenshot of a computer terminal displaying command line options for a program named 'akira\_v2' with various parameters and their descriptions.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-532926-137681-14.png) Figure 14. Akira\_v2 help menu.

This variant targets the following file extensions:

* .vmdk
* .vmem
* .vmx
* .log
* .vswp
* .vmsd
* .vmsn

By using the --stopvm argument, the variant adds the ability to turn off running VMs. It does so by executing the following command:

* vim-cmd vmsvc/getallvms | tail -n +2 | awk '{system("vim-cmd vmsvc/power.off " $1)}'.

Also, Akira\_v2 uses yet another ransom note file, named akiranew.txt, which still points to the same negotiation site used for the original version of Akira ransomware. Akira\_v2 also changes the extension added to encrypted files to .akiranew.

Figure 15 demonstrates how Cortex XDR detects and prevents the Akira\_v2 variant.
![Screen displaying a security alert in Cortex XDR from WildFire Malware detection service, highlighting a suspicious executable named 'akira\_v2.elf'.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-535540-137681-15.png) Figure 15. Howling Scorpius's Akira\_v2 encryptor detected by Cortex XDR.

## Conclusion

This threat assessment demonstrates how Akira ransomware operates, solidifying Howling Scorpius' position among the top five most active ransomware groups despite its relatively recent emergence. The group's developers and affiliates appear to be actively developing new strains and capabilities, as well as making ongoing changes to the toolkit, which contributes to the persistence and prevalence of the ransomware.

We showed how the group used different ransomware variants in tandem, its infection vectors and activity within an infected organization. This group's recent focus on virtualization hosts to affect more endpoints and circumvent security measures means organizations should take the threat seriously and prepare against it.

### Palo Alto Networks Protection and Mitigations

For Palo Alto Networks customers, our products and services provide the following coverage associated with this group:

* [**Advanced WildFire**](https://www.paloaltonetworks.com/products/secure-the-network/wildfire) cloud-delivered malware analysis service accurately identifies known samples as malicious.
* [**Cortex XDR**](https://www.paloaltonetworks.com/cortex/cortex-xdr) and [**XSIAM**](https://docs-cortex.paloaltonetworks.com/p/XSIAM) are designed to:
  * Prevent the execution of known malware and also prevent the execution of unknown malware using [**Behavioral Threat Protection**](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/threat-prevention) and machine learning based on the Local Analysis module.
    * [**Anti-Ransomware Module**](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Prevent-Administrator-Guide/Endpoint-Protection-Modules): It can target encryption-based activities associated with ransomware. It can analyze and halt ransomware activity before data loss occurs, providing proactive protection against the threat discussed in this article.
  * Detect post-exploit activity, including [**credential-based attacks**](https://www.paloaltonetworks.com/resources/techbriefs/cortex-xdr-identity-analytics), with behavioral [**analytics**](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Analytics-Concepts) through Cortex XDR Pro and XSIAM.
* [**Cortex Xpanse**](https://www.paloaltonetworks.com/cortex/cortex-xpanse) can detect internet-exposed RDP servers and VPN services that have been identified as common initial access targets for this group. [**XSIAM**](https://docs-cortex.paloaltonetworks.com/p/XSIAM) customers with the ASM module also have access to these detection capabilities.

If you think you might have been impacted or have an urgent matter, get in touch with the [**Unit 42 Incident Response team**](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America Toll-Free: 866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

Palo Alto Networks has shared these findings, including file samples and indicators of compromise, with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and disrupt malicious cyber actors systematically. Learn more about the [**Cyber Threat Alliance**](https://www.cyberthreatalliance.org/).

## Indicators of Compromise

**SHA256 hashes for examples of Akira ransomware's Windows variant**

* 08207409e1d789aea68419b04354184490ce46339be071c6c185c75ab9d08cba
* 2727c73f3069457e9ad2197b3cda25aec864a2ab8da3c2790264d06e13d45c3d
* 2db4a15475f382e34875b37d7b27c3935c7567622141bc203fde7fe602bc8643
* 56f1014eb2d145c957f9bc0843f4e506735d7821e16355bcfbb6150b1b5f39db
* 58e9cd249d947f829a6021cf6ab16c2ca8e83317dbe07a294e2035bb904d0cf3
* 678ec8734367c7547794a604cc65e74a0f42320d85a6dce20c214e3b4536bb33
* 1ba1ccfacffbb6be9480380f5535a30d3eee1dd7787f3c649ebf8ea2a6a5de51
* 9f873c29a38dd265decb6517a2a1f3b5d4f90ccd42eb61039086ea0b5e74827e
* 1b6af2fbbc636180dd7bae825486ccc45e42aefbb304d5f83fafca4d637c13cc
* cc970bd2673e46c7e0df5430ab617bc2a9214b4d5c2c44252af681a08ff526a8

**SHA256 hashes for examples of Megazord**

* 131da83b521f610819141d5c740313ce46578374abb22ef504a7593955a65f07
* 28cea00267fa30fb63e80a3c3b193bd9cd2a3d46dd9ae6cede5f932ac15c7e2e
* 2f629395fdfa11e713ea8bf11d40f6f240acf2f5fcf9a2ac50b6f7fbc7521c83
* 68d5944d0419bd123add4e628c985f9cbe5362ee19597773baea565bff1a6f1a
* 7f731cc11f8e4d249142e99a44b9da7a48505ce32c4ee4881041beeddb3760be
* 8816caf03438cd45d7559961bf36a26f26464bab7a6339ce655b7fbad68bb439
* 95477703e789e6182096a09bc98853e0a70b680a4f19fa2bf86cbb9280e8ec5a
* 9585af44c3ff8fd921c713680b0c2b3bbc9d56add848ed62164f7c9b9f23d065
* 9f393516edf6b8e011df6ee991758480c5b99a0efbfd68347786061f0e04426c
* a6b0847cf31ccc3f76538333498f8fef79d444a9d4ecfca0592861cf731ae6cb
* b55fbe9358dd4b5825ce459e84cd0823ecdf7b64550fe1af968306047b7de5c9
* c0c0b2306d31e8962973a22e50b18dfde852c6ddf99baf849e3384ed9f07a0d6
* c9c94ac5e1991a7db42c7973e328fceeb6f163d9f644031bdfd4123c7b3898b0
* dfe6fddc67bdc93b9947430b966da2877fda094edf3e21e6f0ba98a84bc53198
* e3fa93dad8fb8c3a6d9b35d02ce97c22035b409e0efc9f04372f4c1d6280a481
* 28cea00267fa30fb63e80a3c3b193bd9cd2a3d46dd9ae6cede5f932ac15c7e2e
* dfe6fddc67bdc93b9947430b966da2877fda094edf3e21e6f0ba98a84bc53198
* 0c0e0f9b09b80d87ebc88e2870907b6cacb4cd7703584baf8f2be1fd9438696d

**SHA256 hashes for examples of Akira ransomware's Linux/ESXi variant**

* 1d3b5c650533d13c81e325972a912e3ff8776e36e18bca966dae50735f8ab296
* 300bc2769c6d62ba9d228cc45e126cd458e1a23fd23092da258053afd82f2755
* 3805f299d33ef43d17a5a1040149f0e5e2d5db57ec6f03c5687ac23db1f77a30
* 3999a25f8f0fd8252aa9250fa9bd70aae202f181812cc6c230c8ea2842340f18
* 3dc7d4023c7380ed740ac5ac7d82a4ba6f587f430b2b7b66f1d34a44f89c39cb
* 43c5a487329f5d6b4a6d02e2f8ef62744b850312c5cb87c0a414f3830767be72
* 6005dcbe15d60293c556f05e98ed9a46d398a82e5ca4d00c91ebec68a209ea84
* 74f497088b49b745e6377b32ed5d9dfaef3c84c7c0bb50fabf30363ad2e0bfb1
* 7ca3e6b4dd4d98506faa92ab590108cacb2945b8c27dcf1ac75b0df4a206493a
* 82e25f32e01f1898ccce2b6d5292245759733c22a104443a8a9c7db1ebf05c57
* 8e9a33809b9062c5033928f82e8adacbef6cd7b40e73da9fcf13ec2493b4544c
* bcae978c17bcddc0bf6419ae978e3471197801c36f73cff2fc88cecbe3d88d1a
* 5f72bdb14e138f10c1658248fdaf10db2fd1e812240966e009bbcf8d463e099c
* 67f82a54ea49c6f286681d179cc7afc8b41b6b34284cc17bdd52916cc3656160
* 6a5e547756ef1256f1eb9df0249245c35461affd009be8f046559bc007cafcf2
* e702a572b514984deacaa54408059c6eac28e46111cb6f0f4190a3a6a72dd41d

**SHA256 hashes for examples of Akira\_v2**

* 0ee1d284ed663073872012c7bde7fac5ca1121403f1a5d2d5411317df282796c
* 3298d203c2acb68c474e5fdad8379181890b4403d6491c523c13730129be3f75

## Additional Resources

* [Ransomware Spotlight: Akira](https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-akira) -- Trend Micro Research
* [#StopRansomware: Akira Ransomware \[PDF\]](https://www.cisa.gov/sites/default/files/2024-04/aa24-109a-stopransomware-akira-ransomware_2.pdf) -- CISA
* [Akira Ransomware is "bringin' 1988 back"](https://news.sophos.com/en-us/2023/05/09/akira-ransomware-is-bringin-88-back/) -- Sophos
* [Akira, again: The ransomware that keeps on taking](https://news.sophos.com/en-us/2023/12/21/akira-again-the-ransomware-that-keeps-on-taking/) -- Sophos
* [Ransomware Roundup - Akira](https://www.fortinet.com/blog/threat-research/ransomware-roundup-akira) -- Fortinet
* [Megazord ransomware analysis](https://www.cynet.com/blog/megazord-ransomware-technical-analysis-and-preventions/) -- Cynet

## Appendices

### Appendix A: Akira Ransomware Windows Variant: Targeted File Extensions

Howling Scorpius Windows encryptors will avoid encrypting files with the following extensions:

* .exe
* .dll
* .lnk
* .sys
* .msi
* .akira

Additionally, the Windows encryptor will avoid the following directories:

* tmp
* thumb
* winnt
* $Recycle.Bin
* temp
* Boot
* Windows
* $RECYCLE.BIN
* System Volume Information
* Trend Micro
* ProgramData

Akira ransomware's Windows encryptors target the following extensions:

|------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Letter Range** | **Extension**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| A-L              | .4dd, .4dl, .abcddb, .abs, .abx, .accdb, .accdc, .accde, .accdr, .accdt, .accdw, .accft, .adb, .ade, .adf, .adn, .adp, .alf, .arc, .ask, .avdx, .avhd, .bdf, .bin, .btr, .cat, .cdb, .ckp, .cma, .cpd, .dacpac, .dad, .dadiagrams, .daschema, .db, .db-shm, .db-wal, .db2, .db3, .dbc, .dbf, .dbs, .dbt, .dbv, .dbx, .dcb, .dct, .dcx, .ddl, .dlis, .dp1, .dqy, .dsk, .dsn, .dtsx, .dxl, .eco, .ecx, .edb, .epim, .exb, .fcd, .fdb, .fic, .fm5, .fmp, .fmp12, .fmpsl, .fol, .fp3, .fp4, .fp5, .fp7, .fpt, .frm, .gdb, .grdb, .gwi, .hdb, .his, .hjt, .ib, .icg, .icr, .idb, .ihx, .iso, .itdb, .itw, .jet, .jtx, .kdb, .kexi, .kexic, .kexis, .lgc, .lut, .lwx |
| M-Z              | .maf, .maq, .mar, .mas, .mav, .maw, .mdb, .mdf, .mdn, .mdt, .mpd, .mrg, .mud, .mwb, .myd, .ndf, .nnt, .nrmlib, .ns2, .ns3, .ns4, .nsf, .nv, .nv2, .nvram, .nwdb, .nyf, .odb, .oqy, .ora, .orx, .owc, .p96, .p97, .pan, .pdb, .pdm, .pnz, .pvm, .qcow2, .qry, .qvd, .raw, .rbf, .rctd, .rod, .rodx, .rpd, .rsd, .sas7bdat, .sbf, .scx, .sdb, .sdc, .sdf, .sis, .spq, .sql, .sqlite, .sqlite3, .sqlitedb, .subvol, .te, .temx, .tmd, .tps, .trc, .trm, .udb, .udl, .usr, .v12, .vdi, .vhd, .vhdx, .vis, .vmcx, .vmdk, .vmem, .vmrs, .vmsd, .vmsn, .vmx, .vpd, .vsv, .vvv, .wdb, .wmdb, .wrk, .xdb, .xld, .xmlff                                                  |

### Appendix B: Megazord Termination Commands

* cmd.exe /c net stop "IBM Domino Diagnostics (CProgramFilesIBMDomino)"
* cmd.exe /c net stop "IBM Domino Server (CProgramFilesIBMDominodata)"
* cmd.exe /c net stop "Simply Accounting Database Connection Manager"
* cmd.exe /c net stop IISADMIN
* cmd.exe /c net stop MSExchangeADTopology
* cmd.exe /c net stop MSExchangeFBA
* cmd.exe /c net stop MSExchangeIS
* cmd.exe /c net stop MSExchangeSA
* cmd.exe /c net stop MSSQL$ISARS
* cmd.exe /c net stop MSSQL$MSFW
* cmd.exe /c net stop MSSQLServerADHelper100
* cmd.exe /c net stop MSSQLServerADHelper100
* cmd.exe /c net stop QBCFMonitorService
* cmd.exe /c net stop QBPOSDBServiceV12
* cmd.exe /c net stop QBVSS
* cmd.exe /c net stop QuickBooksDB1
* cmd.exe /c net stop QuickBooksDB10
* cmd.exe /c net stop QuickBooksDB11
* cmd.exe /c net stop QuickBooksDB12
* cmd.exe /c net stop QuickBooksDB13
* cmd.exe /c net stop QuickBooksDB14
* cmd.exe /c net stop QuickBooksDB15
* cmd.exe /c net stop QuickBooksDB16
* cmd.exe /c net stop QuickBooksDB17
* cmd.exe /c net stop QuickBooksDB18
* cmd.exe /c net stop QuickBooksDB19
* cmd.exe /c net stop QuickBooksDB2
* cmd.exe /c net stop QuickBooksDB20
* cmd.exe /c net stop QuickBooksDB21
* cmd.exe /c net stop QuickBooksDB22
* cmd.exe /c net stop QuickBooksDB23
* cmd.exe /c net stop QuickBooksDB24
* cmd.exe /c net stop QuickBooksDB25
* cmd.exe /c net stop QuickBooksDB3
* cmd.exe /c net stop QuickBooksDB4
* cmd.exe /c net stop QuickBooksDB5
* cmd.exe /c net stop QuickBooksDB6
* cmd.exe /c net stop QuickBooksDB7
* cmd.exe /c net stop QuickBooksDB8
* cmd.exe /c net stop QuickBooksDB9
* cmd.exe /c net stop ReportServer$ISARS
* cmd.exe /c net stop SPAdminV4
* cmd.exe /c net stop SPSearch4
* cmd.exe /c net stop SPTimerV4
* cmd.exe /c net stop SPTraceV4
* cmd.exe /c net stop SPUserCodeV4
* cmd.exe /c net stop SPWriterV4
* cmd.exe /c net stop SQLAgent$ISARS
* cmd.exe /c net stop SQLAgent$MSFW
* cmd.exe /c net stop SQLBrowser
* cmd.exe /c net stop SQLWriter
* cmd.exe /c net stop ShadowProtectSvc
* cmd.exe /c net stop WinDefend
* cmd.exe /c net stop firebirdguardiandefaultinstance
* cmd.exe /c net stop ibmiasrw
* cmd.exe /c net stop mr2kserv
* cmd.exe /c powershell -command "Get-VM | Stop-VM -Force"
* cmd.exe /c taskkill /f /im CNTAoSMgr\*
* cmd.exe /c taskkill /f /im IBM\*
* cmd.exe /c taskkill /f /im Notifier\*
* cmd.exe /c taskkill /f /im Ntrtscan\*
* cmd.exe /c taskkill /f /im TmListen\*
* cmd.exe /c taskkill /f /im bes10\*
* cmd.exe /c taskkill /f /im black\*
* cmd.exe /c taskkill /f /im chrome\*
* cmd.exe /c taskkill /f /im copy\*
* cmd.exe /c taskkill /f /im ds\_monitor\*
* cmd.exe /c taskkill /f /im dsa\*
* cmd.exe /c taskkill /f /im excel\*
* cmd.exe /c taskkill /f /im firefox\*
* cmd.exe /c taskkill /f /im iVPAgent\*
* cmd.exe /c taskkill /f /im iexplore\*
* cmd.exe /c taskkill /f /im mysql\*
* cmd.exe /c taskkill /f /im outlook\*
* cmd.exe /c taskkill /f /im postg\*
* cmd.exe /c taskkill /f /im putty\*
* cmd.exe /c taskkill /f /im robo\*
* cmd.exe /c taskkill /f /im sage\*
* cmd.exe /c taskkill /f /im sql\*
* cmd.exe /c taskkill /f /im ssh\*
* cmd.exe /c taskkill /f /im store.exe
* cmd.exe /c taskkill /f /im tasklist\*
* cmd.exe /c taskkill /f /im taskmgr\*
* cmd.exe /c taskkill /f /im vee\*
* cmd.exe /c taskkill /f /im veeam\*
* cmd.exe /c taskkill /f /im wrsa\*
* cmd.exe /c taskkill /f /im wrsa.exe

### Appendix C: Akira Ransomware Linux\\ESXi Variant: Targeted File Extensions

Akira ransomware's Linux\\ESXi encryptors will avoid encrypting files with the following extensions, the same as the Windows encryptors:

* .exe
* .dll
* .lnk
* .sys
* .msi
* .akira

Additionally, the Linux\\ESXi encryptor will avoid the following directories:

* tmp
* thumb
* winnt
* $Recycle.Bin
* temp
* Boot
* Windows
* $RECYCLE.BIN
* System Volume Information
* Trend Micro
* ProgramData

Akira ransomware's Linux\\ESXi encryptors target the following extensions:

|------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Letter Range** | **Extension**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| A-L              | .4dd, .abcddb, .abs, .abx, .accdb, .accdc, .accde, .accdr, .accdt, .accdw, .accft, .adb, .ade, .adf, .adn, .adp, .alf, .arc, .ask, .avdx, .avhd, .bdf, .bin, .btr, .cat, .cdb, .ckp, .cma, .cpd, .dacpac, .dad, .dadiagrams, .daschema, .db-shm, .db-wa, .db2, .db3, .dbc, .dbf, .dbs, .dbt, .dbv, .dbx, .dcb, .dct, .dcx, .dlis, .dp1, .dqy, .dsk, .dsn, .dtsx, .eco, .ecx, .edb, .epim, .exb, .fcd, .fdb, .fic, .fm5, .fmp, .fmp12, .fmps, .fp3, .fp4, .fp5, .fp7, .fpt, .frm, .gdb, .grdb, .gwi, .hdb, .his, .hjt, .icg, .icr, .idb, .ihx, .iso, .itdb, .itw, .jet, .jtx, .kdb, .kexi, .kexic, .kexis, .lgc, .lut, .lwx |
| M-Z              | .maf, .maq, .mar, .mas, .mav, .maw, .mdb, .mdf, .mdn, .mdt, .mpd, .mrg, .mud, .mwb, .myd, .ndf, .nnt, .nrmlib, .ns2, .ns3, .ns4, .nsf, .nv2, .nvram, .nwdb, .nyf, .odb, .oqy, .ora, .orx, .owc, .p96, .p97, .pan, .pdb, .pdm, .pnz, .pvm, .qcow2, .qry, .qvd, .raw, .rbf, .rctd, .rod, .rodx, .rpd, .rsd, .sas7bdat, .sbf, .scx, .sdb, .sdc, .sdf, .sis, .spq, .sqlite, .sqlite3, .sqlitedb, .subvo, .temx, .tmd, .tps, .trc, .trm, .udb, .usr, .v12, .vdi, .vhd, .vhdx, .vis, .vmcx, .vmdk, .vmem, .vmrs, .vmsd, .vmsn, .vmx, .vpd, .vsv, .vvv, .wdb, .wmdb, .wrk, .xdb, .xld, .xmlff                                     |

Back to top

### Tags

* [Akira ransomware](https://unit42.paloaltonetworks.com/tag/akira-ransomware/ "Akira ransomware")
* [Bring Your Own Driver](https://unit42.paloaltonetworks.com/tag/bring-your-own-driver/ "Bring Your Own Driver")
* [CVE-2020-3259](https://unit42.paloaltonetworks.com/tag/cve-2020-3259/ "CVE-2020-3259")
* [CVE-2023-20269](https://unit42.paloaltonetworks.com/tag/cve-2023-20269/ "CVE-2023-20269")
* [Double extortion](https://unit42.paloaltonetworks.com/tag/double-extortion/ "double extortion")
* [ESXi](https://unit42.paloaltonetworks.com/tag/esxi/ "ESXi")
* [FTP](https://unit42.paloaltonetworks.com/tag/ftp/ "FTP")
* [Howling Scorpius](https://unit42.paloaltonetworks.com/tag/howling-scorpius/ "Howling Scorpius")
* [Lazagne](https://unit42.paloaltonetworks.com/tag/lazagne/ "Lazagne")
* [Leak site](https://unit42.paloaltonetworks.com/tag/leak-site/ "Leak site")
* [Linux](https://unit42.paloaltonetworks.com/tag/linux/ "Linux")
* [Megazord](https://unit42.paloaltonetworks.com/tag/megazord/ "Megazord")
* [Mimikatz](https://unit42.paloaltonetworks.com/tag/mimikatz/ "Mimikatz")
* [Remote desktop](https://unit42.paloaltonetworks.com/tag/remote-desktop/ "remote desktop")
* [Rust](https://unit42.paloaltonetworks.com/tag/rust/ "Rust")
* [Server Message Block](https://unit42.paloaltonetworks.com/tag/server-message-block/ "Server Message Block")
* [Torrenting](https://unit42.paloaltonetworks.com/tag/torrenting/ "torrenting")
* [Windows](https://unit42.paloaltonetworks.com/tag/windows/ "Windows")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Threat Brief: Operation Lunar Peek, Activity Related to CVE-2024-0012 and CVE-2024-9474 (Updated Nov. 22)](https://unit42.paloaltonetworks.com/cve-2024-0012-cve-2024-9474/ "Threat Brief: Operation Lunar Peek, Activity Related to CVE-2024-0012 and CVE-2024-9474 (Updated Nov. 22)")

### Table of Contents

* 

### Related Articles

* [The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "article - table of contents")
* [Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "article - table of contents")
* [No Manners Here: The Ruthless Rise of The Gentlemen Ransomware](https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/ "article - table of contents")

## Related Resources

![Pictorial representation of Russian global webmail espionage campaign. A digital illustration of a world map in a network style, highlighting continents with glowing lines and connectivity points in a red and blue theme.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/06_Nation-State-cyberattacks_1920x900-1-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 23, 2026 [#### Russian Global Webmail Espionage](https://unit42.paloaltonetworks.com/russian-webmail-espionage/)

* [CL-STA-1114](https://unit42.paloaltonetworks.com/tag/cl-sta-1114/ "CL-STA-1114")

* [JavaScript](https://unit42.paloaltonetworks.com/tag/javascript/ "JavaScript")

* [Javascript injection](https://unit42.paloaltonetworks.com/tag/javascript-injection/ "javascript injection")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/russian-webmail-espionage/ "Russian Global Webmail Espionage")  
  ![Pictorial representation of a woman standing in a server room holding a laptop that projects a digital code overlay.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) May 28, 2026 [#### 2026 World Cup: Discussing The World's Biggest Game's Attack Surface](https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/)

* [Fiddling Scorpius](https://unit42.paloaltonetworks.com/tag/fiddling-scorpius/ "Fiddling Scorpius")

* [Fighting Ursa](https://unit42.paloaltonetworks.com/tag/fighting-ursa/ "Fighting Ursa")

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/ "2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface")  
  ![Pictoral representation of a man holding a cellphone with a bokeh skyline in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Listicle_Category_1505x922-718x440.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) May 27, 2026 [#### Out of the Crypt: The Evolving Cyber Extortion Economy](https://unit42.paloaltonetworks.com/cyber-extortion-economy/)

* [Bling Libra](https://unit42.paloaltonetworks.com/tag/bling-libra/ "Bling Libra")

* [Extortion](https://unit42.paloaltonetworks.com/tag/extortion/ "Extortion")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cyber-extortion-economy/ "Out of the Crypt: The Evolving Cyber Extortion Economy")  
  ![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) April 17, 2026 [#### Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/tag/apk/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/tag/ddos-attacks/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/ "Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)")  
  ![Pictorial representation of the APT Boggy Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/Boggy-Serpens-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) March 16, 2026 [#### Boggy Serpens Threat Assessment](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Boggy Serpens](https://unit42.paloaltonetworks.com/tag/boggy-serpens/ "Boggy Serpens")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/ "Boggy Serpens Threat Assessment")  
  ![Pictorial representation of Muddled Libra, aka Scattered Spider. A vibrant illustration of the Libra zodiac sign, featuring a stylized balance scale overlaid with a prominent Libra symbol. The background is a starry night sky with shades of purple and blue, suggesting a cosmic theme.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/03-1-Muddle-Libra-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) February 10, 2026 [#### A Peek Into Muddled Libra's Operational Playbook](https://unit42.paloaltonetworks.com/muddled-libra-ops-playbook/)

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")

* [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/ "PowerShell")

* [Scattered Spider](https://unit42.paloaltonetworks.com/tag/scattered-spider/ "Scattered Spider")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/muddled-libra-ops-playbook/ "A Peek Into Muddled Libra’s Operational Playbook")  
  ![Pictorial representation of a group of individuals discussing an idea with a whiteboard.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/02_Listicle_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) February 3, 2026 [#### Why Smart People Fall For Phishing Attacks](https://unit42.paloaltonetworks.com/psychology-of-phishing/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/psychology-of-phishing/ "Why Smart People Fall For Phishing Attacks")  
  ![Pictorial representation of threat groups from Russia. The silhouette of a bear and the Ursa constellation inside an orange abstract planet. Abstract, stylized cosmic setting with vibrant blue and purple shapes, representing space and distant planetary bodies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/Ursa-Russia-B-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) January 29, 2026 [#### Understanding the Russian Cyberthreat to the 2026 Winter Olympics](https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [IoT](https://unit42.paloaltonetworks.com/tag/iot/ "IoT")

* [Russia](https://unit42.paloaltonetworks.com/tag/russia/ "Russia")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/ "Understanding the Russian Cyberthreat to the 2026 Winter Olympics")  
  ![Pictorial representation of RaaS RansomHouse. Digital representation of cybersecurity concept with a padlock superimposed over computer circuit boards, symbolizing data protection and encryption technologies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/06_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 17, 2025 [#### From Linear to Complex: An Upgrade in RansomHouse Encryption](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/)

* [ESXi](https://unit42.paloaltonetworks.com/tag/esxi/ "ESXi")

* [Jolly Scorpius](https://unit42.paloaltonetworks.com/tag/jolly-scorpius/ "Jolly Scorpius")

* [RansomHouse](https://unit42.paloaltonetworks.com/tag/ransomhouse/ "RansomHouse")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/ "From Linear to Complex: An Upgrade in RansomHouse Encryption")  
  ![Pictorial representation of 01flip ransomware written in Rust. Digital artwork of a pixelated U.S. dollar bill disintegrating into small blocks against a blue data matrix background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 10, 2025 [#### 01flip: Multi-Platform Ransomware Written in Rust](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/)

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [CL-CRI-103](https://unit42.paloaltonetworks.com/tag/cl-cri-103/ "CL-CRI-103")

* [Cryptocurrency](https://unit42.paloaltonetworks.com/tag/cryptocurrency/ "Cryptocurrency")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/ "01flip: Multi-Platform Ransomware Written in Rust")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/content/pan/en_US/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
