Akira ransomware operators breached a multinational agriculture company through an unpatched single-factor VPN appliance and then exploited the VMware vCenter Server remote code execution flaw CVE-2021-21972 to deepen access inside the victim environment. VMware had previously issued VMSA-2021-0002 to address the vulnerability in ESXi and vCenter Server, but in this intrusion the exposed weakness enabled the attackers to compromise vCenter and pivot into the organization’s virtual infrastructure.
After taking control of vCenter, the attackers created a new virtual machine in the ESXi environment, mounted copied VMDK files from a powered-down domain controller, and extracted NTDS.dit and the SYSTEM hive to obtain highly privileged credentials. With domain administrator access, Akira moved laterally, exfiltrated data, and deployed ransomware in under six hours, using a legacy Veritas Backup Exec Client service and network shares for distribution along with tools including NetCat, RustDesk, AnyDesk, WinSCP, WinRAR, and network scanners; the tradecraft was notable for abusing virtualization layers to evade conventional EDR visibility and was reported to resemble activity previously linked to UTA0178.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
S-RM released a report detailing the intrusion, including the use of vCenter compromise, attacker-created virtual machines, NTDS.dit extraction, and tooling such as RustDesk, AnyDesk, WinSCP, WinRAR, NetCat, and network scanners. The report also noted similarities to activity previously attributed to China-linked actor UTA0178 and shared indicators including repairdll[.]net/jHKIOEyC/.
Using credentials derived from NTDS.dit and the SYSTEM hive, Akira compromised a highly privileged domain administrator account, moved laterally, exfiltrated data, and deployed ransomware in under six hours. The group distributed ransomware via network shares and the legacy Veritas Backup Exec Client service.
Following the vCenter compromise, Akira created a new virtual machine on the ESXi environment, powered down a domain controller VM, copied its VMDK files, and attached them to the attacker-created VM. This let the attackers extract NTDS.dit and the SYSTEM hive outside normal endpoint monitoring.
After obtaining VPN access, the attackers exploited CVE-2021-21972 on VMware vCenter, uploaded a malicious JSP file named healthcheck_beat.jsp, and used it to execute commands and establish a reverse shell with NetCat.
In early 2024, Akira ransomware operators accessed a multinational agriculture company through an unpatched single-factor VPN appliance. This initial foothold preceded exploitation of the victim's VMware environment.
VMware published advisory VMSA-2021-0002 addressing multiple vulnerabilities in ESXi and vCenter Server, including CVE-2021-21972, the vCenter uploadOVA remote code execution flaw later exploited in the Akira intrusion.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.