Threats & Adversaries · Ransomware

Akira Executes Full Ransomware Attacks in Under One Hour

The Akira ransomware group now completes entire attacks in less than an hour by chaining exploitation of internet-facing VPN and backup appliances (SonicWall, Veeam, Cisco) with credential theft and initial access brokers. They use living-off-the-land tools like FileZilla and RClone for stealthy data exfiltration and encryption, often encrypting only 1% of files to speed impact. This rapid, disciplined tempo leaves almost no time for detection or manual response, invalidating standard incident playbooks.

Organizations with exposed VPN or backup appliances lacking MFA are at highest risk. Detection should focus on unusual use of legitimate tools and rapid exfiltration. Backup strategies must assume exfiltration can precede encryption and prioritize immutable, air-gapped copies. This is not a zero-day emergency but a critical operational shift demanding faster, automated defenses and hardened credential hygiene.

2 sources · Apr 2

Timeline

Sources

Vendor digest: Cisco

Vendor digest: SonicWall

Part of the PlainSec briefing for 2026-04-03

Every edition of this story: Akira Executes Full Ransomware Attacks in Under One Hour

More from today