Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs, (Wed, May 27th)
This report details the reconstruction of an Akira ransomware attack on a mid-sized organization, focusing on the critical early stages of the intrusion. The analysis, based solely on firewall and Windows event logs, reveals a brute-force attack targeting a vulnerable SSLVPN account, followed by credential stuffing and lateral movement using RDP. The investigation highlights the importance of monitoring log joins between perimeter security and endpoint logs for early detection of attacks, particularly those leveraging known vulnerabilities and techniques like Kerberoasting.
The incident involved an Akira ransomware attack that began with a brute-force assault against a single SSLVPN account. The attacker, utilizing a hosting provider's IP range, successfully authenticated and immediately gained access to the organization's network. Crucially, the account had been disabled in Active Directory but remained provisioned as a local firewall user, a common oversight. The attack’s success demonstrates the vulnerability of organizations relying on legacy systems and lacking robust multi-factor authentication (MFA) controls. The attacker then leveraged this initial foothold for lateral movement, utilizing RDP to access internal resources, including file servers, domain controllers, and backup servers. This movement was facilitated by reconnaissance activities, such as shadow copy analysis, indicating pre-staging for the final encryption stage. The attacker’s actions, including clearing the jump host’s security event log and disabling endpoint protection, demonstrate a sophisticated understanding of defensive techniques and a rapid escalation to maximize the impact of the attack. The lack of traditional security tools like Endpoint Detection and Response (EDR) and PCAPs further emphasized the importance of proactive log monitoring and analysis.
