{
  "Event": {
    "analysis": "1",
    "date": "2026-06-12",
    "extends_uuid": "",
    "info": "[Threat Intel] Akira, LimeWire, and the Sour Taste of Data Exfiltration",
    "protected": false,
    "publish_timestamp": "1782230753",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1782230753",
    "uuid": "bb394d28-549f-4209-a897-d318fd04266f",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#8f20d0",
        "local": false,
        "name": "misp-galaxy:producer=\"Huntress\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Archive via Utility - T1560.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#aff0ae",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Permission Groups Discovery - T1069\"",
        "relationship_type": ""
      },
      {
        "colour": "#3eb869",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Local Data Staging - T1074.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Domain Account - T1087.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d7034",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"",
        "relationship_type": ""
      },
      {
        "colour": "#68f2ff",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#0c0051",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"",
        "relationship_type": ""
      },
      {
        "colour": "#1cbe6b",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Virtualization/Sandbox Evasion - T1497\"",
        "relationship_type": ""
      },
      {
        "colour": "#a9f8b1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"",
        "relationship_type": ""
      },
      {
        "colour": "#e43954",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#59699c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"",
        "relationship_type": ""
      },
      {
        "colour": "#36d931",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#3970d7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Remote System Discovery - T1018\"",
        "relationship_type": ""
      },
      {
        "colour": "#4c0fbb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"",
        "relationship_type": ""
      },
      {
        "colour": "#370063",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Remote Desktop Protocol - T1021.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#297c25",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:ransomware=\"Akira\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#120044",
        "local": false,
        "name": "rectifyq:sub-category=\"intrusion-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#f1dfed",
        "local": false,
        "name": "rectifyq:TA-category=\"Ransomware\"",
        "relationship_type": ""
      },
      {
        "colour": "#d92121",
        "local": false,
        "name": "rectifyq:target=\"targeted\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781578843",
        "to_ids": false,
        "type": "link",
        "uuid": "4601e8f0-1b22-426b-8bd6-81c9c71dae93",
        "value": "https://www.huntress.com/blog/akira-ransomware-limewire-data-exfiltration"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781578843",
        "to_ids": false,
        "type": "text",
        "uuid": "5386aa21-be2d-4fdb-b24b-79da27c09872",
        "value": "In a recent ransomware attack, threat actors accessed a victim's hypervisor and created a new virtual machine to stage and launch Akira ransomware. The forensic investigation revealed the attackers disabled Microsoft Defender immediately, installed WinRAR for data staging, and used Easyupload.io, a file transfer website owned by LimeWire, for data exfiltration. The threat actor also utilized WinSCP and enumerated Active Directory users and computers. The newly instantiated VM lacked security tooling, allowing the attacker to operate uninhibited. Analysis of the VHDX file provided clear evidence of the attack progression, showing the threat actor moved quickly through their operations without employing sophisticated anti-forensics techniques. The incident highlights the need for organizations to monitor environments for unusual access and new endpoint creation."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781578843",
        "to_ids": false,
        "type": "text",
        "uuid": "ac75863f-a50d-4d11-9edb-14bc6026ad90",
        "value": "Name: Akira, LimeWire, and the Sour Taste of Data Exfiltration\nAuthor: AlienVault\nAdversary: Storm-1567\nTags: [\"active directory enumeration\", \"hypervisor compromise\", \"akira\", \"data exfiltration\", \"akira ransomware\", \"limewire\", \"virtual machine staging\", \"winscp\", \"winrar\"]\nTgtd countries: []\nMlwr families: [\"Akira\"]\nAttack_ids: [\"T1560.001\", \"T1069\", \"T1074.001\", \"T1087.002\", \"T1082\", \"T1005\", \"T1140\", \"T1083\", \"T1497\", \"T1041\", \"T1562.001\", \"T1078\", \"T1486\", \"T1567.002\", \"T1018\", \"T1105\", \"T1021.001\", \"T1490\"]\nIndustries: []"
      },
      {
        "category": "Attribution",
        "comment": "Adversary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781578843",
        "to_ids": false,
        "type": "threat-actor",
        "uuid": "768e2e84-37f4-46e2-9dc7-ebe3888d99fd",
        "value": "Storm-1567"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781578843",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "5ab5f650-5629-458b-ba4c-ef9ad96d5c81",
        "value": "CVE-2025-26399"
      },
      {
        "category": "Payload delivery",
        "comment": "Akira encryptor file No sample in VT\r\nLast check:22/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782101777",
        "to_ids": true,
        "type": "sha256",
        "uuid": "7605a29d-e746-470d-b4df-c31a2226bf74",
        "value": "131877a052f62750d815cf55d4c14f606a26025e3094e1b8bb18bd1668e3beaa",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      }
    ]
  }
}