A global data storage and infrastructure company suffered a destructive ransomware attack orchestrated by the Akira ransomware group, also known as Howling Scorpius. The attack began when an employee was tricked by a fake CAPTCHA on a compromised website, leading to the download of SectopRAT malware. This initial compromise allowed the attackers to establish a foothold, conduct reconnaissance, escalate privileges, and move laterally across the network, ultimately gaining access to domain controllers and cloud resources. Over a 42-day period, the attackers used advanced social engineering and technical tactics to evade detection and prepare for the final stage of the attack.
The attackers exploited cloud misconfigurations to destroy backups, crippling the victim's ability to recover data. The use of a CAPTCHA decoy and the targeting of cloud backups highlight evolving ransomware tactics aimed at maximizing operational disruption and ransom leverage. This incident underscores the importance of comprehensive security visibility, robust backup protection, and user awareness to defend against sophisticated, multi-stage ransomware campaigns that blend social engineering with technical exploitation.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 publicly documented the attack, describing how a fake CAPTCHA lure led to a prolonged Akira ransomware compromise. The report provided technical details on the intrusion chain and attacker behavior.
The intrusion culminated in a major ransomware impact attributed to Akira after 42 days of attacker activity in the environment. The attack crippled a storage-focused organization and followed the earlier destruction of backup resources.
During the intrusion, the attackers targeted the victim's cloud backups and storage infrastructure, undermining recovery options. This increased the operational impact and reduced the victim's ability to restore affected systems.
The attackers conducted discovery and lateral movement across the environment, escalating their reach into additional systems. Their activity enabled access to critical infrastructure and storage-related assets.
After initial access, the intruders deployed tools and established persistence to maintain access in the victim network. They used the foothold to begin internal reconnaissance and prepare for broader compromise.
A user was tricked by a fake CAPTCHA prompt into running a malicious PowerShell command, giving the attackers initial access to the victim environment. This marked the beginning of the Akira ransomware intrusion later analyzed as lasting 42 days.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.