Akira Ransomware๋ "Bringin '1988 Back"์ ๋๋ค.
2023๋ 4์ 6์ผ, Sophos ๋์ ํ์ ๋ถ๋ฏธ์ ๋์ฌ์จ์ด ํผํด์ ์กฐ์ง์ ์ง์ํ๊ธฐ ์ํด ์ฐธ์ฌํ์ผ๋ฉฐ, ๋ค์ ์ฃผ 2023๋ 4์ 12์ผ์ ๋ ๋ค๋ฅธ ๋ถ๋ฏธ๊ธฐ๊ตฌ๊ฐ Sophos์๊ฒ ์ฐ๋ฝํ๊ธฐ ์ํด ์ฐ๋ฝํ์ต๋๋ค. ๋ ๊ฐ์ง ์ฌ๊ฑด ๋ชจ๋, ๋์ฌ์จ์ด๋ Akira๋ฅผ ๋ฐฐ์นํ๊ณ , โ.akiraโ ํ์ฅ์์ ์ํธํ๋ ํ์ผ, Fn.txt๋ผ๋ ๋ ธํธ ํ์ผ์ด ํ๋ก์ธ์ค์ ์ญ์ ๋์์ต๋๋ค. ์ด Akira ๋์ฌ์จ์ด๋ 2017๋ ์ ํ์ฑํ๋ ๋์ผํ ์ด๋ฆ์ ์ด์ ๋์ฌ์จ์ด ๋ณํ๊ณผ ์ฝ๋ ์ ์ฌ์ฑ์ ๊ฐ์ง๊ณ ์์ผ๋ฉฐ, ์๋ก์ด jQuery ๊ธฐ๋ฐ ๋์ถ ์ฌ์ดํธ๋ฅผ ํตํด ๋ช ๋ น์ ์๋ฝํ๋ ๋์ ์ ๋ณด๋ฅผ ๋์ดํฉ๋๋ค.
2023๋ 4์ 6์ผ, Sophos ๋์ ํ์ด ๋ถ๋ฏธ์ ๋์ฌ์จ์ด ํผํด์ ์กฐ์ง์ ์ง์ํ๊ธฐ ์ํด ์ฐธ์ฌํ ๋ค, ๋ค์ ์ฃผ 2023๋ 4์ 12์ผ์ ๋ ๋ค๋ฅธ ๋ถ๋ฏธ๊ธฐ๊ตฌ๊ฐ Sophos์๊ฒ ์ฐ๋ฝํ๊ธฐ ์ํด ์ฐ๋ฝํ์ต๋๋ค. ๋ ๊ฐ์ง ์ฌ๊ฑด ๋ชจ๋, ๋์ฌ์จ์ด๋ Akira๋ฅผ ๋ฐฐ์นํ๊ณ , โ.akiraโ ํ์ฅ์์ ์ํธํ๋ ํ์ผ, Fn.txt๋ผ๋ ๋ ธํธ ํ์ผ์ด ํ๋ก์ธ์ค์ ์ญ์ ๋์์ต๋๋ค. ์ด Akira ๋์ฌ์จ์ด๋ 2017๋ ์ ํ์ฑํ๋ ๋์ผํ ์ด๋ฆ์ ์ด์ ๋์ฌ์จ์ด ๋ณํ๊ณผ ์ฝ๋ ์ ์ฌ์ฑ์ ๊ฐ์ง๊ณ ์๊ณ , ์๋ก์ด jQuery ๊ธฐ๋ฐ ๋์ถ ์ฌ์ดํธ๋ฅผ ํตํด ์ ๋ณด
Akira Ransomware is โbringinโ 1988 backโ
On April 6, 2023, the SOPHOS response team participated in supporting North American ransomware victims, and another North American Organization contacted SOPHOS on April 12, 2023 next week.In both events, ransomware deployed Akira, and a โ.akiraโ extension and encrypted file, Fn.txt were deleted into the process.This AKIRA ransomware has the same name of the same name, which was activated in 2017, and has a similarity of code, and lists information instead of accepting commands through the new JQuery -based leak site.
On April 6, 2023, the SOPHOS response team participated in supporting the Ransomware victims in North America, and on April 12, 2023, another North American Organization contacted SOPHOS.In both events, ransomware placed Akira, and a โ.akiraโ extension, encrypted file, fn.txt was deleted into the process.This AKIRA ransomware has the same name of the same name, which was activated in 2017, and has a similarity of code, and information through a new JQuery -based leak site
https://news.sophos.com/en-us/2023/05/09/akira-ransomware-is-bringin-88-back/