<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/akira-ransomware-expands-to-nutanix-ahv-posing-new-threats-to-enterprises-yl6lytuxb" -->

---
title: Akira Ransomware Expands to Nutanix AHV, Posing New...
description: The Akira ransomware group has expanded operations to target Nutanix AHV virtual machines alongside VMware ESXi and Hyper-V, shifting focus from SMBs to large...
canonical: https://daily.dev/posts/akira-ransomware-expands-to-nutanix-ahv-posing-new-threats-to-enterprises-yl6lytuxb
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Akira Ransomware Expands to Nutanix AHV, Posing New Threats to Enterprises | daily.dev
og:description: The Akira ransomware group has expanded operations to target Nutanix AHV virtual machines alongside VMware ESXi and Hyper-V, shifting focus from SMBs to large...
og:url: https://daily.dev/posts/akira-ransomware-expands-to-nutanix-ahv-posing-new-threats-to-enterprises-yl6lytuxb
og:image: https://api.daily.dev/og/posts/Yl6LYtUxb.png
og:image:alt: Akira Ransomware Expands to Nutanix AHV, Posing New Threats to Enterprises
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Akira Ransomware Expands to Nutanix AHV, Posing New Threats to Enterprises

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

The Akira ransomware group has expanded operations to target Nutanix AHV virtual machines alongside VMware ESXi and Hyper-V, shifting focus from SMBs to large enterprises in manufacturing, IT, healthcare, finance, and government sectors. CISA and FBI warn that the group has amassed $244.17 million by exploiting VPNs without MFA, vulnerabilities in Cisco and SonicWall products, and backup server security gaps. Akira uses double-extortion tactics with ChaCha20 encryption, exfiltrating data within two hours of access and leveraging tools like Mimikatz for credential dumping and AdFind for Active Directory reconnaissance. Organizations should implement network segmentation, monitor hypervisor consoles, enforce strict privilege management, audit inherited infrastructure during mergers, and regularly rehearse recovery plans.

## Content

The Akira ransomware group has significantly expanded its operations, now specifically targeting Nutanix AHV virtual machines in addition to their previous focus on VMware ESXi and Hyper-V. This shift underlines a broader strategic pivot from targeting small and medium-sized businesses (SMBs) to large enterprises across critical sectors such as manufacturing, IT, healthcare, finance, and government. 

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have issued warnings regarding Akira's increasing threat landscape. The cybercriminal organization claims to have amassed $244.17 million in proceeds. In their attacks, they exploit poorly secured virtual private networks (VPNs) that lack multifactor authentication (MFA), known vulnerabilities in Cisco and SonicWall products, and security gaps in backup servers such as Veeam.

Akira employs sophisticated double-extortion tactics, exfiltrating data within two hours of gaining initial access and encrypting files using ChaCha20 encryption with an RSA key exchange. This threat scenario is compounded during mergers and acquisitions, where the ransomware operators exploit inherited vulnerabilities within SonicWall SSL VPN appliances and other unsecured legacy systems, leading to attacks on parent company networks. These attacks are often facilitated by neglected legacy credentials and insufficient endpoint protection.

An updated advisory from CISA highlights the ransomware's intricate methods of operation, including credential dumping via Mimikatz and LaZagne, lateral movement leveraging RDP and SSH, and Active Directory reconnaissance conducted with AdFind. AttackIQ has released an updated attack graph that models Akira's behavior, providing organizations with the tools to validate their security controls against these post-compromise tactics.

Organizations are strongly advised to bolster their defenses by segmenting networks, rigorously monitoring hypervisor consoles, implementing strict privilege management, and ensuring robust backup strategies. Additionally, a complete audit of inherited infrastructures during mergers and a rotation of legacy credentials are crucial to preemptively address potential vulnerabilities. 

Security teams should also integrate technical, legal, and communication strategies into their recovery plans and regularly rehearse these plans to ensure swift and effective responses to ransomware threats. Continuous updates to security measures and collaboration with pertinent cybersecurity advisories are key actions to counter the evolving tactics of Ransomware-as-a-Service operations like Akira.

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#infrastructure](https://daily.dev/tags/infrastructure), [#vulnerability](https://daily.dev/tags/vulnerability), [#ransomware](https://daily.dev/tags/ransomware)

[View this post on daily.dev](https://daily.dev/posts/akira-ransomware-expands-to-nutanix-ahv-posing-new-threats-to-enterprises-yl6lytuxb)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Akira Ransomware Expands to Nutanix AHV, Posing New Threats to Enterprises","url":"https://daily.dev/posts/akira-ransomware-expands-to-nutanix-ahv-posing-new-threats-to-enterprises-yl6lytuxb","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/akira-ransomware-expands-to-nutanix-ahv-posing-new-threats-to-enterprises-yl6lytuxb"},"datePublished":"2025-11-17T12:31:58.427Z","dateModified":"2025-11-25T22:44:08.895Z","description":"The Akira ransomware group has expanded operations to target Nutanix AHV virtual machines alongside VMware ESXi and Hyper-V, shifting focus from SMBs to large...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1c922b1889a9e38da1aab6eeafcd5ef5?_a=AQAEulh","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1c922b1889a9e38da1aab6eeafcd5ef5?_a=AQAEulh","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/akira-ransomware-expands-to-nutanix-ahv-posing-new-threats-to-enterprises-yl6lytuxb","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,infrastructure,vulnerability,ransomware","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Akira Ransomware Expands to Nutanix AHV, Posing New Threats to Enterprises"}]}
```

