Akira Ransomware Escalates: Nutanix AHV Virtual Machines Targeted in High-Risk Attacks

Listen to this Post

Featured Image
The US government and multiple cybersecurity agencies have issued an urgent warning: the Akira ransomware gang has expanded its attack strategy to target Nutanix AHV virtual machines. This alarming development signals a growing sophistication in ransomware operations, as cybercriminals increasingly focus on virtualized environments critical to enterprise infrastructure. With attackers now capable of encrypting Nutanix VM disk files, organizations using this platform face heightened risk, making proactive defenses and rapid incident response more crucial than ever.

Akira Ransomware Expands to Nutanix AHV

In a joint advisory from CISA, the FBI, the Department of Defense Cyber Crime Center (DC3), the Department of Health and Human Services (HHS), and international partners, Akira ransomware has been confirmed to encrypt Nutanix AHV virtual machine disk files. Initially observed in June 2025, this represents a significant shift as Akira moves beyond previously targeted platforms like VMware ESXi and Hyper-V. The attack exploits a SonicWall vulnerability (CVE-2024-40766) that allows unauthorized access through improper controls.

Nutanix AHV, a Linux-based virtualization platform widely deployed in enterprise environments, now joins the list of high-value targets. Unlike VMware ESXi, where Akira uses platform-specific commands to gracefully shut down VMs before encryption, Nutanix AHV VMs are directly targeted by encrypting .qcow2 files, the virtual disk format for the platform, without any graceful shutdown. This difference suggests Akira’s attack on Nutanix is still evolving but poses a serious threat to unprepared organizations.

Evolving Intrusion Techniques

The updated advisory also sheds light on Akira’s methods for breaching corporate networks. Affiliates frequently exploit stolen or brute-forced VPN and SSH credentials, alongside SonicWall vulnerabilities, to gain initial access. From there, attackers target unpatched Veeam Backup & Replication servers (CVE-2023-27532 and CVE-2024-40711) to compromise or delete backups, further amplifying potential damage.

Once inside, Akira employs a range of tools—including nltest, AnyDesk, LogMeIn, and Impacket’s wmiexec.py—to map networks, move laterally, and establish persistent administrative access. They often remove endpoint detection tools, create new admin accounts, and in one case, powered down a domain controller VM to extract credentials directly from its VMDK files. Akira has also abandoned older tools, like “Megazord,” while adopting tunneling solutions like Ngrok to maintain encrypted command-and-control channels that evade network monitoring.

Strengthening Defenses

The advisory underscores the importance of immediate defensive actions: enforcing multifactor authentication, maintaining regular offline backups, and patching known vulnerabilities quickly. Given Akira’s capability to exfiltrate data in as little as two hours, organizations must adopt proactive monitoring and incident response strategies.

What Undercode Say: Strategic Implications of Akira’s Nutanix Targeting

Akira’s pivot to Nutanix AHV highlights a critical trend in ransomware evolution: targeting virtualization platforms that underpin enterprise operations. Virtual machines store not only operational workloads but also sensitive corporate data, making them prime ransomware targets. By bypassing platform-specific shutdown procedures and encrypting VM disk files directly, Akira simplifies its attack chain, reducing the chance of operational disruptions that could alert administrators early.

This approach signals a strategic focus on maximizing impact while minimizing detection, reflecting the growing sophistication of modern ransomware. Enterprises relying on Nutanix AHV, VMware ESXi, or Hyper-V should assume attackers will exploit both unpatched vulnerabilities and human error. Credential compromise remains a primary attack vector, emphasizing the need for strict access controls and continuous network monitoring.

Moreover, Akira’s rapid data exfiltration capability combined with the use of tunneling tools like Ngrok demonstrates a dual threat: immediate encryption damage and potential exposure of sensitive data. This mirrors the broader industry trend of “double extortion” ransomware, where attackers demand ransom not only for restoring access but also to prevent public data leaks.

From a risk management perspective, organizations should implement layered defenses: network segmentation to isolate critical workloads, frequent integrity checks on VM disk files, and automated backup verification processes. Security teams must also recognize that defending virtualized environments requires specialized monitoring tools capable of detecting unauthorized VM file access or unusual shutdown patterns.

Akira’s activity underscores the importance of international collaboration. By combining intelligence across CISA, FBI, DC3, HHS, and global partners, organizations gain access to a comprehensive set of Indicators of Compromise (IoCs) and attack signatures, essential for anticipating future TTPs (Tactics, Techniques, and Procedures) used by ransomware gangs.

Finally, Akira’s evolving threat to Nutanix AHV VMs should be seen as an early warning for enterprises: if one ransomware family successfully adapts to new virtualization platforms, others are likely to follow. Proactive threat modeling, vulnerability scanning, and incident simulation exercises will be key to staying ahead.

Fact Checker Results

✅ Akira ransomware has been confirmed targeting Nutanix AHV virtual machines since June 2025.
✅ The ransomware exploits SonicWall vulnerabilities and unpatched Veeam Backup servers to gain access.
❌ Akira’s Nutanix AHV attacks are not yet as sophisticated as its VMware ESXi operations.

Prediction

📊 Expect Akira and similar ransomware groups to increasingly target enterprise virtualization platforms, including Nutanix AHV, VMware, and Hyper-V.
📊 Companies will likely face a rise in dual-threat attacks: encryption plus data exfiltration.
📊 Organizations adopting robust patching, offline backups, and MFA will significantly reduce attack success rates, while lagging enterprises may see accelerated losses in both operational continuity and sensitive data.

If you want, I can also make a more SEO-optimized, punchy version for tech news blogs that grabs clicks while keeping all these analytics. Do you want me to do that next?

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.reddit.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon