Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Tuesday, 9 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Privilege escalation: unravelling a novel cyber-attack technique

By Jamie Smith, Global Head of Cyber Security Services at S-RM

by The Gurus
July 23, 2024
in Featured
Privilege escalation: unravelling a novel cyber-attack technique
Share on FacebookShare on Twitter

Cyber criminals are notoriously relentless and unforgiving in their quest to exploit vulnerabilities through ever-evolving tactics. Organisations may believe that their security frameworks are robust, but when confronted with unprecedented attack methods, nobody is entirely immune to infiltration.

Earlier this year, a multinational agriculture company learnt this the hard way when they fell victim to a novel technique called privilege escalation. S-RM’s Incident Response team was called in and quickly identified Akira as the ransomware group behind the breach. Since this technique was new and unknown, traditional security measures were rendered ineffective, allowing the attackers ample time to infiltrate systems, exfiltrate data, and inflict damage.

Who are Akira?

Since emerging onto the cyber scene in March last year, Akira has honed its sights on small-to medium-sized organisations across North America, Europe, and Australia. The group’s Tactics, Techniques and Procedures (TTPs) typically involve infiltrating target organisations via their VPNs, either by exploiting compromised credentials or vulnerabilities within the VPN software.

Laying the foundations for privilege escalation

As is often the case when Akira is involved, the initial breach was traced to vulnerabilities within the company’s VPN software. In this case, the initial intrusion was traced to an unpatched single-factor VPN appliance, which handed attackers access to the company’s network and laid the foundations for a full blown attack.

Once connected to the network via the VPN, Akira leveraged a remote code execution vulnerability in the VMware vCenter server, allowing the unauthenticated attackers to upload a web shell to the vulnerable endpoint. Subsequently, the threat actor could implant a reverse shell and had gained remote access to the vCenter server.

Having accessed the company’s vCenter, the attackers created a new virtual machine on a VMware ESXi hypervisor. This machine gave Akira free rein to conduct their operations undetected, evading conventional Endpoint Detection and Response tools.

Privilege escalation and gaining full control

Not satisfied with acquiring local administrator privileges for the newly spawned VM, Akira sought elevated access for lateral movement across the target domain. Their approach involved extracting credentials from the NTDS.dit file, the Active Directory database that resides on each domain controller and stores user account data, including password hashes. This database is robustly protected, through both system protections and encryption using a key stored in the SYSTEM registry hive. Attackers generally require elevated privileges in order to dump hashes from the NTDS.dit file.

Akira bypassed the VMKD file’s protections using a novel series of steps. Initially, the threat actor temporarily powered down the domain controller’s virtual machine and then copied the associated VMDK files to a separate directory. Then, they attached these copied virtual hard drives to the newly created VM, allowing them to proceed with their attack.

Akira was able to copy and compress the NTDS.dit file using the 7-zip and exfiltrate the SYSTEM hive. Now armed with the decryption key for the password hashes, Akira would have been able to crack the hashes or utilise ‘pass-the-hash’ methods for user authentication. By following this novel formula to extract the NTDS.dit file, Akira was able to compromise a highly privileged domain administrator’s account.

With elevated privileges attained, Akira navigated swiftly across the network, compromising additional user accounts, withdrawing data and deploying ransomware – all in under six hours.

Exploiting privilege escalation for ransomware deployment

Akira was able to deploy ransomware in two ways: via network shares and remote backup services. Specifically, the threat actor leveraged the legitimate Veritas Backup Exec Client process ‘beremote.exe’ to deploy a randomly generated 8-character ransomware binary to servers where the backup software was present. Exploiting backup shares to deploy ransomware is a rarity as cyber criminals often aim to destroy it to render recovery efforts ineffective. However, as this backup service was already a part of the organisation’s ecosystem, it likely served as a means to bypass security defences.

Lessons learned

Akira’s exploits serve as stark reminder for all that attackers are constantly looking for vulnerabilities and will punish existing weaknesses in a ruthless manor. Cyber criminals excel in innovation and adaptability. If cracks exist, you can be sure they’ll find a way through.

Taking a proactive approach is the best way to build a robust defence system. Organisations need to maintain updated security, both for the external perimeter and the in-network devices. Regular security updates and a robust patch management system are good practice staying one step ahead of cyber criminals. This not only helps to stop quick lateral movements across the network but also gives extra time to respond effectively to threats.

Other measures, like multi-factor authentication, a consistent patching policy, and regular security assessments, can also go a long way to reduce the risk of falling victim to ransomware attacks like those carried out by Akira at the beginning of the year.

Above all else, this attack is evidence that companies are locked in a constant battle to keep attackers at bay. Cyber-criminals aren’t about let up in their efforts to take advantage of any weakness. Fending them off is a question of matching their efforts and more when it comes to regularly strengthening your defence framework.

 

By Jamie Smith, Global Head of Cyber Security Services at S-RM

ShareTweet
Previous Post

Worldwide IT Outages: Cybersecurity Experts Weigh In

Next Post

Enhancing the cybersecurity talent pool is key to securing our digital future

Recent News

Frontline Workers Twice as Likely to Use Unapproved AI

Frontline Workers Twice as Likely to Use Unapproved AI

June 4, 2026
Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
data-cloud-security

Building a Digital Fortress: Why Cyber Security Matters More Than Ever

June 5, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol