Akira attacks Energy One
The Akira Ransomware Gang's Attack on Energy One
The Akira ransomware gang has attacked Energy One. Energy One is an Australian software company that specializes in providing software solutions for the energy industry. It was founded in 2001 and is headquartered in Brisbane, Australia. The company's primary focus is on developing and offering software solutions and services to help energy companies manage various aspects of their operations more effectively.
Akira posted Energy One to its data leak site on September 6th but provided no further details. The Akira ransomware gang, first identified in May 2023, utilizes the Windows Restart Manager API to effectively close processes or terminate Windows services that might be actively using a file, thereby allowing the encryption process to proceed unhindered. In each computer folder affected by the ransomware, a ransom note named "akira_readme.txt" is placed. This note serves as a communication from the attackers, explaining the situation and providing links to the Akira data leak site and negotiation site.
The Ransom Note's Warning
The ransom note issued by the Akira group contains a chilling warning: "Regarding your data, in the event that we fail to reach an agreement, we will attempt to sell your personal information, trade secrets, databases, source codes, and anything else deemed valuable on the dark market to multiple threat actors simultaneously. Subsequently, all of this compromised information will be publicly exposed on our blog."
Method of Operation
Like to other ransomware groups, the Akira gang infiltrates corporate networks and expands its reach to other connected devices. After acquiring Windows domain admin credentials, the threat actors deploy their ransomware across the entire network. Before encrypting the files, the attackers take the additional step of exfiltrating sensitive corporate data. This stolen information is then used as leverage during their extortion tactics, as they warn victims that the data will be made public unless a ransom payment is made.
The Akira gang has invested considerable effort into designing their data leak website, which features a retro aesthetic and allows visitors to navigate through it using command inputs.
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!