{"id":1891,"date":"2025-02-11T10:03:34","date_gmt":"2025-02-11T10:03:34","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/02\/11\/akira-ransomware-leads-the-number-of-ransomware-attacks-for-january-2025\/"},"modified":"2025-02-11T10:03:34","modified_gmt":"2025-02-11T10:03:34","slug":"akira-ransomware-leads-the-number-of-ransomware-attacks-for-january-2025","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/02\/11\/akira-ransomware-leads-the-number-of-ransomware-attacks-for-january-2025\/","title":{"rendered":"Akira Ransomware Leads The Number of Ransomware Attacks For January 2025"},"content":{"rendered":"<p>    Akira Ransomware Leads The Number of Ransomware Attacks For January 2025<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>January 2025 marked a significant month in the ransomware landscape, with Akira emerging as the leading threat.<\/p>\n<p>According to recent reports, Akira was responsible for 72 attacks globally, highlighting its rapid rise in prominence.<\/p>\n<p>This surge in activity is part of a broader trend where <a href=\"https:\/\/cybersecuritynews.com\/ransomware-groups-attacking-satellite\/\" target=\"_blank\" rel=\"noreferrer noopener\">ransomware groups<\/a> are becoming increasingly sophisticated in their tactics and targets.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi21XRw9HD0ATSB5jetoBXOsBx9pyVolskInhF-S3ieMWCBBUuL6KOh-lRqqdu4_vG8DSKIkvGeQMpM_FFz3_ydILKGjCvWKzruIc5uNslfqEE105tqze5stQE2ikHJk2zmecsA1Q9dka7g6ZLOOfbGOTCMfoa1ivJk04TZmz5qtLRztsyY5xwxS0-FnFY\/s16000\/Ransomware%2520Trends%2520Graph%2520%28Source%2520-%2520Cyfirma%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Ransomware Trends Graph (Source \u2013 Cyfirma)<\/figcaption><\/figure>\n<\/div>\n<p>In January, Akira emerged as the most active ransomware group, with a 60% increase in activity due to its effective use of Python-based malware and <a href=\"https:\/\/cybersecuritynews.com\/microsoft-sharepoint-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">exploitation<\/a> of critical infrastructure vulnerabilities.<\/p>\n<p>Meanwhile, new ransomware groups like MORPHEUS and Gd Lockersec have entered the scene, with MORPHEUS claiming three victims since December 2024 and Gd Lockersec targeting five by the end of January.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhNTw8LaCgBhhDFMO5lCh8VAhc6dy7s_T3FHZLlqESVM-8Ort3QLJFcZQEj4NJPQCNd3bQe-swi5wpfSVRNxfL2U6j7GRxM9dRPKY0Uuk7APXNGgI5Q7nwQRlUudcx0OyA5eqmwRdNV1C43zsq7GXh2fdKZxPmEcLyfDoc8HrICBHIldcQbM6SaVgssuxA\/s16000\/MORPHEUS%2520Onion%2520Site%2520%28Source%2520-%2520Cyfirma%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">MORPHEUS Onion Site (Source \u2013 Cyfirma)<\/figcaption><\/figure>\n<\/div>\n<p>MORPHEUS and HellCat share a codebase, deploying 64-bit executable payloads that exclude certain system files from <a href=\"https:\/\/cybersecuritynews.com\/windows-11-bitlocker-encryption-bypassed\/\" target=\"_blank\" rel=\"noreferrer noopener\">encryption<\/a>, while Gd Lockersec focuses on financial gains and avoids attacking entities in specific countries and non-profit hospitals.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjqtc6n9WjI3oyRPjEep965K2Pel57RW1LGk-mnvPl8Enfyve8UtyvO5QKz3UwDrBsdTOlIOS-HhZSlQv_fsiiQ9dbCfMyO9oYnrpGea9aUVW1jk1dv5sc0-UbEu9CZr3Ci2Iza5XCGmMw-sqGhWADe3vybakOLaKcY4pOYjAiCJER-j14MOn1JyMe5USU\/s16000\/Gd%2520Lockersec%2520Onion%2520Site%2520%28Source%2520-%2520Cyfirma%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Gd Lockersec Onion Site (Source \u2013 Cyfirma)<\/figcaption><\/figure>\n<\/div>\n<p>The Manufacturing sector remained the primary target, with 75 reported incidents, while the IT sector saw a 60% increase due to its critical data and supply chain access.<\/p>\n<p>While besides this, the security researchers at Cyfirma <a href=\"https:\/\/www.cyfirma.com\/research\/tracking-ransomware-january-2025\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that geographically, the United States was the most targeted region, with 259 incidents, followed by Canada, the UK, France, and Germany\u2014nations frequently targeted for their strong economies and data-rich enterprises.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjihjRKBgtX8tPZT-OmwYpqYgvROv6lxmjlI4br9qkTimTIx-s3gI59KA0wOAHZGwW5JMv1-HcLfDDrEgaJX-YRUMJz3Cm-QlZsAKDxXUbeD1MOWIfPT-FYXmD545UPZNaRbmdziGVAFHT64-4iYiisIjBHpwRRkwhFXp6ZeR5Hv96Mgo91J56HLrMFa1g\/s16000\/Top%2520Locations%2520Targeted%2520%28Source%2520-%2520Cyfirma%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Top Locations Targeted (Source \u2013 Cyfirma)<\/figcaption><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading\"><strong>Akira Attack Chain<\/strong><\/h2>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Python-Based Malware<\/strong>: Ransomware groups are increasingly using Python-based backdoors for network infiltration.<\/li>\n<\/ul>\n<p>These backdoors establish SOCKS5 tunnels, facilitating lateral movement and ransomware deployment while evading detection.<\/p>\n<pre class=\"wp-block-code\"><code>  # Example of Python-based backdoor code\n  import socket\n  import socks\n\n  # Establishing a SOCKS5 connection\n  socks.setdefaultproxy(socks.PROXY_TYPE_SOCKS5, '127.0.0.1', 9050)\n  socks.wrapmodule(socket)\n\n  # Creating a reverse proxy for communication\n  def create_reverse_proxy():\n      # Code to handle reverse proxy logic\n      pass<\/code><\/pre>\n<ul class=\"wp-block-list\">\n<li>\n<strong>VMware ESXi Exploitation<\/strong>: Threat actors are targeting VMware ESXi hypervisors using SSH tunnels to establish persistence and deploy ransomware. This approach exploits the critical role of ESXi in virtualized infrastructures.<\/li>\n<\/ul>\n<pre class=\"wp-block-code\"><code>  # Example of SSH tunneling command\n  ssh -L 8080:localhost:8080 user@esxi-host<\/code><\/pre>\n<p>The ransomware landscape in January 2025 was marked by increased sophistication and targeted attacks.<\/p>\n<p>With such rapid evolution it is crucial for organizations to enhance their <a href=\"https:\/\/cybersecuritynews.com\/non-negotiable-for-payroll-compliance\/\" target=\"_blank\" rel=\"noreferrer noopener\">cybersecurity measures<\/a>.<\/p>\n<p>This includes monitoring for Python-based malware, securing VMware ESXi systems, and implementing robust access controls.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code><strong><code>Are you from SOC\/DFIR Team? - Join 500,000+ Researchers to Analyze Cyber Threats with ANY.RUN Sandbox -\u00a0<a href=\"https:\/\/any.run\/demo\/?utm_source=li_csn&amp;utm_medium=post&amp;utm_campaign=meme&amp;utm_content=demo&amp;utm_term=100225\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try for Free<\/a><\/code><\/strong><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/akira-ransomware-leads-the-number-of-ransomware-attacks\/\">Akira Ransomware Leads The Number of Ransomware Attacks For January 2025<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/akira-ransomware-leads-the-number-of-ransomware-attacks\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Akira Ransomware Leads The Number of Ransomware Attacks For January 2025 January 2025 marked a significant month in the ransomware landscape, with Akira emerging as the leading threat. According to recent reports, Akira was responsible for 72 attacks globally, highlighting its rapid rise in prominence. This surge in activity is part of a broader trend [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63,700,231],"tags":[130],"class_list":["post-1891","post","type-post","status-publish","format-standard","hentry","category-cyber-security-news","category-cyberattack-news","category-ransomware","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1891"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=1891"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1891\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=1891"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=1891"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=1891"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}