Akira Ransomware๋Š” "Bringin '1988 Back"์ž…๋‹ˆ๋‹ค

Akira Ransomware๋Š” "Bringin '1988 Back"์ž…๋‹ˆ๋‹ค.

2023๋…„ 4์›” 6์ผ, Sophos ๋Œ€์‘ ํŒ€์€ ๋ถ๋ฏธ์˜ ๋žœ์„ฌ์›จ์–ด ํ”ผํ•ด์ž ์กฐ์ง์„ ์ง€์›ํ•˜๊ธฐ ์œ„ํ•ด ์ฐธ์—ฌํ–ˆ์œผ๋ฉฐ, ๋‹ค์Œ ์ฃผ 2023๋…„ 4์›” 12์ผ์— ๋˜ ๋‹ค๋ฅธ ๋ถ๋ฏธ๊ธฐ๊ตฌ๊ฐ€ Sophos์—๊ฒŒ ์—ฐ๋ฝํ•˜๊ธฐ ์œ„ํ•ด ์—ฐ๋ฝํ–ˆ์Šต๋‹ˆ๋‹ค. ๋‘ ๊ฐ€์ง€ ์‚ฌ๊ฑด ๋ชจ๋‘, ๋žœ์„ฌ์›จ์–ด๋Š” Akira๋ฅผ ๋ฐฐ์น˜ํ–ˆ๊ณ , โ€œ.akiraโ€ ํ™•์žฅ์ž์™€ ์•”ํ˜ธํ™”๋œ ํŒŒ์ผ, Fn.txt๋ผ๋Š” ๋…ธํŠธ ํŒŒ์ผ์ด ํ”„๋กœ์„ธ์Šค์— ์‚ญ์ œ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ด Akira ๋žœ์„ฌ์›จ์–ด๋Š” 2017๋…„์— ํ™œ์„ฑํ™”๋œ ๋™์ผํ•œ ์ด๋ฆ„์˜ ์ด์ „ ๋žœ์„ฌ์›จ์–ด ๋ณ€ํ˜•๊ณผ ์ฝ”๋“œ ์œ ์‚ฌ์„ฑ์„ ๊ฐ€์ง€๊ณ  ์žˆ์œผ๋ฉฐ, ์ƒˆ๋กœ์šด jQuery ๊ธฐ๋ฐ˜ ๋ˆ„์ถœ ์‚ฌ์ดํŠธ๋ฅผ ํ†ตํ•ด ๋ช…๋ น์„ ์ˆ˜๋ฝํ•˜๋Š” ๋Œ€์‹  ์ •๋ณด๋ฅผ ๋‚˜์—ดํ•ฉ๋‹ˆ๋‹ค.

2023๋…„ 4์›” 6์ผ, Sophos ๋Œ€์‘ ํŒ€์ด ๋ถ๋ฏธ์˜ ๋žœ์„ฌ์›จ์–ด ํ”ผํ•ด์ž ์กฐ์ง์„ ์ง€์›ํ•˜๊ธฐ ์œ„ํ•ด ์ฐธ์—ฌํ•œ ๋’ค, ๋‹ค์Œ ์ฃผ 2023๋…„ 4์›” 12์ผ์— ๋˜ ๋‹ค๋ฅธ ๋ถ๋ฏธ๊ธฐ๊ตฌ๊ฐ€ Sophos์—๊ฒŒ ์—ฐ๋ฝํ•˜๊ธฐ ์œ„ํ•ด ์—ฐ๋ฝํ–ˆ์Šต๋‹ˆ๋‹ค. ๋‘ ๊ฐ€์ง€ ์‚ฌ๊ฑด ๋ชจ๋‘, ๋žœ์„ฌ์›จ์–ด๋Š” Akira๋ฅผ ๋ฐฐ์น˜ํ•˜๊ณ , โ€œ.akiraโ€ ํ™•์žฅ์ž์™€ ์•”ํ˜ธํ™”๋œ ํŒŒ์ผ, Fn.txt๋ผ๋Š” ๋…ธํŠธ ํŒŒ์ผ์ด ํ”„๋กœ์„ธ์Šค์— ์‚ญ์ œ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ด Akira ๋žœ์„ฌ์›จ์–ด๋Š” 2017๋…„์— ํ™œ์„ฑํ™”๋œ ๋™์ผํ•œ ์ด๋ฆ„์˜ ์ด์ „ ๋žœ์„ฌ์›จ์–ด ๋ณ€ํ˜•๊ณผ ์ฝ”๋“œ ์œ ์‚ฌ์„ฑ์„ ๊ฐ€์ง€๊ณ  ์žˆ๊ณ , ์ƒˆ๋กœ์šด jQuery ๊ธฐ๋ฐ˜ ๋ˆ„์ถœ ์‚ฌ์ดํŠธ๋ฅผ ํ†ตํ•ด ์ •๋ณด

Akira Ransomware is โ€œbringinโ€™ 1988 backโ€

On April 6, 2023, the SOPHOS response team participated in supporting North American ransomware victims, and another North American Organization contacted SOPHOS on April 12, 2023 next week.In both events, ransomware deployed Akira, and a โ€œ.akiraโ€ extension and encrypted file, Fn.txt were deleted into the process.This AKIRA ransomware has the same name of the same name, which was activated in 2017, and has a similarity of code, and lists information instead of accepting commands through the new JQuery -based leak site.

On April 6, 2023, the SOPHOS response team participated in supporting the Ransomware victims in North America, and on April 12, 2023, another North American Organization contacted SOPHOS.In both events, ransomware placed Akira, and a โ€œ.akiraโ€ extension, encrypted file, fn.txt was deleted into the process.This AKIRA ransomware has the same name of the same name, which was activated in 2017, and has a similarity of code, and information through a new JQuery -based leak site

https://news.sophos.com/en-us/2023/05/09/akira-ransomware-is-bringin-88-back/