Threat reportRansomwareTL-2026-2852
The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)
The First 24 Hours of a Ransomware Intrusion (TL-2026-2852), also tracked as Akira ransomware, is a high-severity ransomware operation, first published 2026-10-03. It is attributed to Akira with medium confidence, affects SonicWall SonicOS SSL VPN, references 5 CVEs (CVE-2024-40766, CVE-2023-28252, CVE-2024-37085), maps to 19 MITRE ATT&CK techniques (T1003.001, T1003.002, T1003.003), and is covered by 9 detection rules and 31 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 5Referenced vulnerabilities
- Techniques
- 19MITRE ATT&CK
- Actors
- 1Akira
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 31Indicators of compromise
Key facts for TL-2026-2852
- Threat ID
- TL-2026-2852
- Also known as
- Akira ransomware, Akira_v2, Megazord
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- Akira
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- education, manufacturing, information-technology, health, finance, food-and-agriculture
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 31
Malware and tooling in The First 24 Hours of a Ransomware Intrusion
Malware and tooling: AgendaCrypt, Akira, Akira (ELF), Akira _v2 - S1194, Cobalt Strike, Mega, Megazord - S1191, MimiKatz, POORTRY, STONESTOP, STOP Ransomware, SystemBC - S9001
How The First 24 Hours of a Ransomware Intrusion works
Huntress-hosted guest article walks through the first 24 hours of a ransomware incident, citing Mandiant M-Trends 2026 (14-day median dwell time; 22-second initial-access-to-ransomware-affiliate hand-off) and the CISA/FBI Akira advisory (data theft completed in just over two hours in some cases). The CISA Akira update documents the VPN-without-MFA vector, edge and backup-software CVEs, exfiltration tooling (FileZilla, WinRAR, WinSCP, RClone, Mega, Ngrok) and credential theft (Mimikatz, LaZagne, LSASS, Kerberoasting).
This item is incident-response guidance rather than a new variant disclosure, but it consolidates operator tradecraft that is corroborated by the CISA #StopRansomware Akira advisory (AA24-109A, originally published 2024-04-18 and updated 2025-11-13 with the FBI, DC3, HHS, Europol EC3 and French, German and Dutch agencies).
Initial access and speed. The CISA update names VPN services without multi-factor authentication as a primary Akira entry vector, together with password spraying (SharpDomainSpray) and brute-forcing of VPN endpoints. Edge and infrastructure CVEs used for initial access or escalation are CVE-2024-40766 (SonicWall, improper access control), CVE-2023-28252 (heap-based buffer overflow), CVE-2024-37085 (authentication bypass), CVE-2023-27532 and CVE-2024-40711 (Veeam Backup; the latter a deserialization flaw). Mandiant M-Trends 2026 reports the median time from an initial access broker foothold to hand-off to a ransomware affiliate fell to 22 seconds in 2025 (from over eight hours in 2022), while global median dwell time rose to 14 days from 11.
Credential theft and discovery. The article cites Mimikatz and LaZagne for credential dumping, LSASS memory extraction and Kerberoasting against service accounts. CISA adds SAM and NTDS dumping, NetExec (including the --dpapi option), Impacket and nltest domain-controller and trust enumeration (nltest /dclist:, nltest /DOMAIN_TRUSTS). Lateral movement and C2 tooling named by CISA includes Cobalt Strike, SystemBC, POORTRY and STONESTOP loaders, LogMeIn, OpenSSH, Cloudflared and Ngrok.
Exfiltration. Staging and compression use FileZilla, WinRAR and 7-zip; transfer uses WinSCP, RClone, FTP/SFTP and the Mega cloud storage service; Ngrok provides encrypted tunnels that bypass perimeter monitoring. CISA documents data theft completed in just over two hours from initial access in some cases. Because these are legitimate tools, the article advises hunting on outbound volume and destination (unusual volume to a consumer cloud endpoint off-hours) rather than on signatures.
Impact and backup targeting. M-Trends 2026 reports operators actively targeting backup infrastructure, identity services and virtualization management planes; volume shadow copies are frequently removed with PowerShell. CISA documents PowerShell and WMIC used to disable services, firewall modification, and encryptors: Akira/Akira_v2 (.akira, .akiranew, .aki; Rust-based), the deprecated Megazord variant (.powerranges) and a Linux/ESXi encryptor that also targets Nutanix AHV. Ransom notes are fn.txt or akira_readme.txt. CISA states Akira has claimed about $244.17 million in proceeds as of late September 2025 and primarily targets small and medium-sized businesses, with a notable preference for educational institutions.
The article also names REDBIKE and AGENDA in the context of backup-infrastructure targeting; it provides no specific IPs, hashes or hostnames. The two SHA-256 hashes below come from the CISA advisory, not the article. The article's statistics are second-hand citations; Akira details were corroborated against the CISA advisory, and M-Trends figures against the Google Cloud M-Trends 2026 coverage.
MITRE ATT&CK techniques used in TL-2026-2852
Credential Access
T1003.001 LSASS Memory; T1003.002 Security Account Manager; T1003.003 NTDS; T1110.003 Password Spraying; T1555 Credentials from Password Stores; T1558.003 Kerberoasting
Exfiltration
T1048 Exfiltration Over Alternative Protocol; T1567.002 Exfiltration to Cloud Storage
Execution
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
Command and Control
T1219 Remote Access Tools; T1572 Protocol Tunneling
Discovery
Impact
T1489 Service Stop; T1490 Inhibit System Recovery
Collection
Defense Impairment
Affected products and versions in The First 24 Hours of a Ransomware Intrusion
Remediation for The First 24 Hours of a Ransomware Intrusion
Patches
- Patch CVE-2024-40766 (SonicWall), CVE-2024-37085 (VMware ESXi), CVE-2023-27532 and CVE-2024-40711 (Veeam Backup) and CVE-2023-28252 (Windows CLFS)
Immediate actions
- Enforce phishing-resistant MFA on all VPN and remote-access paths
- Isolate affected hosts via EDR; disable compromised accounts and reset krbtgt twice if credential theft is confirmed
- Hunt outbound volume and destination for FileZilla, WinSCP, RClone, Mega and Ngrok use
- Verify backup server does not authenticate against the compromised domain and that immutability is enabled
Workarounds
- Close VPN access without MFA until MFA is enforced
- Restrict and monitor remote administration and tunneling tools (Ngrok, Cloudflared, LogMeIn)
Longer-term hardening
- Test a full end-to-end backup restore and keep offline/immutable backups
- Document incident decision authority with named deputies and run tabletop exercises
- Rebuild identity infrastructure (clean domain controller) first during recovery
- Rotate service-account passwords that predate the intrusion
CVEs associated with The First 24 Hours of a Ransomware Intrusion
CVE-2024-40766, CVE-2023-28252, CVE-2024-37085, CVE-2023-27532, CVE-2024-40711
Weaknesses (CWE) in The First 24 Hours of a Ransomware Intrusion
Timeline of The First 24 Hours of a Ransomware Intrusion
- Per Mandiant M-Trends 2026, median initial-access-to-ransomware-affiliate hand-off was still over eight hours as recently as 2022 (approximate year; no exact date given)
- CISA, FBI and partners publish the original #StopRansomware: Akira Ransomware advisory (AA24-109A)
- As of late September 2025, Akira has claimed approximately $244.17 million in ransomware proceeds (CISA; approximate date)
- AA24-109A updated with new TTPs and IOCs: VPN without MFA, new CVEs, Akira_v2, Linux/ESXi encryptor, SystemBC, Cloudflared and other tooling; co-sealed by Europol EC3 and French, German and Dutch agencies
- Mandiant M-Trends 2026 reports global median dwell time of 14 days (up from 11) and a 22-second median initial-access-to-ransomware-affiliate hand-off in 2025 (month approximate)
- Huntress publishes guest article 'The First 24 Hours: What Actually Happens When Ransomware Lands' by UnderDefense CEO Nazar Tymoshyk
Sources cited for The First 24 Hours of a Ransomware Intrusion
- The First 24 Hours: What Actually Happens When Ransomware Lands (Huntress)
- #StopRansomware: Akira Ransomware (CISA AA24-109A)
- FBI IC3 CSA: Akira Ransomware update
- FBI IC3 CSA: Akira Ransomware (original advisory)
- M-Trends 2026: Data, Insights, and Strategies From the Frontlines (Google Cloud / Mandiant)
- M-Trends 2026 Report (Executive Edition)
- AttackIQ: Updated Response to CISA Advisory AA24-109A
- SafeBreach: Coverage for Updated CISA AA24-109A Akira Ransomware
- Mandiant M-Trends 2026: ransomware hand-off time of 22 seconds
Detection coverage for TL-2026-2852
As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2852 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.