Ako Ransomware
Ako, also known as MedusaReborn, is a newly observed ransomware tool targeting larger business networks. Despite being used in several active campaigns it appears to still be in active development, with its creators offering daily beta versions for attackers to use.
Summary
Ako, also known as MedusaReborn, is a newly observed ransomware tool targeting larger business networks. Despite being used in several active campaigns it appears to still be in active development, with its creators offering daily beta versions for attackers to use.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how Ako its delivered, although the nature of its intended targets indicates it may be distributed manually via exposed network equipment.
Once installed, Ako will attempt to delete Volume Shadow Copies and disable recovery services. It will then begin to encrypt all files that do not match a hard-coded list using an unknown algorithm. Whilst this is happening, Ako will scan the affected network for any connected devices or drives for it to propagate to.
Threat updates
| Date | Update |
|---|---|
| 21 May 2020 |
Ako now also steals data and demands an additional ransom to prevent its release on a dedicated leak website. |
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Indicators of compromise
Last edited: 29 June 2021 12:00 pm