For MSP & IT Decision-Makers

    How Acronis stops a ransomware attack. Step by step.

    We follow a real attack from Akira - one of the world's most dangerous ransomware groups - and show where Acronis stops each step.

    Real attack, not theory
    7 attack steps analyzed
    Source: FBI · CISA
    Ongoing attack
    Live simulation
    Actor
    Akira ransomware
    Time to data theft: < 2 hours
    Acronis stops it at step 1. Every layer below is a new chance to stop the attack.
    Monday morning · 08:47

    Are you ready for this call?

    This is what it sounds like when Akira has just hit your largest customer.

    It's 08:50 AM. Akira has already been in the network for 11 days.

    The question is not if the call will come - but if you are prepared when it does.

    Who is the attacker

    Meet Akira

    Active global threat
    $0M
    Extorting companies since 2023
    + $0 just i denna session
    Average ransom~ $1.5M
    SourceFBI · CISA

    One of the world's most profitable ransomware groups right now.

    #0
    World #2 by 2026
    TrendFrom #4 (2024)
    TargetMid-market & enterprise

    Rapidly growing. Targets mid-sized and large enterprises.

    < 0h
    Time to data theft
    Median53 minutes
    Fastest confirmed19 minutes

    Akira often manages to steal data before your security team has even reacted.

    Akira is not just a hacking group - it's an entire organization. Technicians, salespeople, and negotiators work in parallel. To stop them, you need coverage at all levels.

    01Break-in

    How the attacker gets their first key.

    1. 1
      A fake Microsoft login tricks the user into giving up their password.
    2. 2
      With the account, the attacker accesses Microsoft 365 and your shared spaces.
    3. 3
      Malicious files are placed in SharePoint - they appear internal.
    4. 4
      Colleagues click and give up their passwords. The attacker gains broader access.
    Inbox
    Microsoft Security09:14
    Verify your password - account locked
    We detected suspicious activity. Click here to unlock your Microsoft 365 account within 24 hours...
    sender: security-microsoft@mail-verify-365.cn
    Blocked
    Email & Collaboration Security stops the email before it reaches the inbox.
    02Creeping the net

    Using your own tools against you.

    Akira uses common IT tools that are already present in your environment. This makes them hard to detect.

    Lateral movement - live
    $
    $
    Risk level: critical0%

    Mapping the network

    Common IT tools quietly map your network.

    > 10.0.1.42 [DC01]
    > 10.0.1.55 [FILE-SRV]
    > 10.0.2.78 [BACKUP]
    217 hosts
    mapped
    Reconnaissance in progress0%

    Jumping between systems

    Windows tools move the attacker between servers.

    PCSERVERDC
    RDPPsExecWMISMB
    [INTERNAL] No alerts triggered
    Spreading0%

    Stealing passwords

    Passwords are extracted from Active Directory.

    47hashes extracted
    Escalation0%
    2 843 s
    Time spent in network
    0
    Detected by legacy AV
    3
    Created backdoor accounts
    03Disabling defenses

    How the attacker shuts down your protection.

    Windows Defender is disabled with a command.
    PowerTool force-quits EDR processes.
    BYOVD bypasses endpoint protection.
    Runs evenings and weekends, when alarms are not monitored.
    Defense kill chain - reconstruction
    00 / 04
    1. 02:14:03Defender disabled...
    2. 02:14:47EDR process killed...
    3. 02:15:12Vulnerable driver loaded...
    4. 02:15:38Security logs cleared...
    akira-c2 @ DC01-AD ~ #
    $
    $
    $
    $
    MITRE ATT&CKT1562.001Disable or Modify ToolsT1068Privilege EscalationT1070.001Indicator RemovalT1078Valid Accounts
    Protection falls

    Alarms are off. The attacker works undisturbed for hours.

    Alarms last night
    Lör 02:14:07
    - No security analyst on site.

    An alarm without anyone listening is worthless. What makes a difference is that the alarm cannot be turned off - and that someone actually responds.

    "Akira affiliates have been observed disabling endpoint detection tooling within minutes of initial access, often during weekends and overnight hours."

    - FBI · CISA Joint Advisory, 2024
    04Stealing the data

    The real weapon.

    rclone exfil → mega.io
    PID 4127
    0.00 TB/ 2.30 TB
    Speed
    310 MB/s
    Files
    0
    ETA
    00:09
    Live file feed
    Potential GDPR fine (4% of revenue)
    € 2 847 000
    The clock starts ticking the moment data leaves the network.
    Goal
    Everything of value
    Personal data
    Contracts
    Source code
    Financial data

    Everything that can be used to pressure you into paying.

    Business model
    Double extortion
    ~ 70%
    Pays
    $1,5M
    Average ransom

    Two invoices per attack: one to unlock files, one not to leak them.

    Channels
    Common cloud services
    Mega.ioRcloneFileZillaWinSCPMASSCAN

    Data is smuggled out via services you already trust. The firewall sees nothing unusual.

    Stolen data is the real threat today. Backup saves operations - but not leaks. Once data is out, the GDPR clock starts ticking.

    Calculate your GDPR fines
    05Destroying backups

    The goal: you should have no choice.

    Akira destroys all your backups before encryption starts. You either pay - or lose everything.

    Backup status - LIVE
    0 / 12 destroyed
    Protection level100%
    DC01-AD
    12 min ago
    FILE-SRV
    47 min ago
    SQL-PROD
    8 min ago
    EXCH-MBX
    23 min ago
    NAS-01
    1h 5m ago
    NAS-02
    1h 11m ago
    VEEAM-REPO
    5 min ago
    TAPE-LIB
    3h 0m ago
    WEB-PROD
    17 min ago
    DEV-DB
    39 min ago
    BACKUP-SRV
    3 min ago
    ARCHIVE-VOL
    3h 40m ago
    OK Stale Failed
    1.2 TB deleted
    Immutable Cloud
    HEALTHY
    0 % intact
    Air-gapped
    Last successful4 min ago
    Restorations/day847 OK
    RPO< 15 min
    01

    Deleting shadow copies

    Windows restore points are deleted.

    No local recovery
    02

    Disabling backup servers

    Local backup servers are attacked.

    NAS, tape, local copies are disabled
    03

    Encrypting everything

    Ransomware is rolled out across systems.

    Files locked, ransom demand displayed
    DEFENSE

    Locked cloud backups

    Separate from the network. Cannot be deleted - even by admin.

    You can always restore
    06Fighting back

    How to stop the attacker in the middle of the attack.

    One console. One agent

    A single console and one agent per computer. You see everything in one place.

    Stopping processes

    Immediately stop suspicious programs and unauthorized connections.

    Isolating machines

    Cut the attacker's connections and remove affected machines from the network - with one click.

    Without a unified platform you're chasing the attacker blindly, across hundreds of computers, with different tools. When every second counts, scattered systems are the attacker's best friend.

    Acronis XDR + RMM combined
    Detection
    0:02s
    Assessment
    0:30s
    Isolation
    1:10s
    Restored
    08:00
    07Back in operation

    From backup to operation in minutes.

    Loss right now - without recovery environment
    € 12 847
    Operations are at a standstill. Every second of downtime costs wages, missed orders, SLA fines, and lost trust.
    With Acronis Disaster Recovery
    € 1 240
    The recovery environment starts within minutes. The bleeding is stopped before customers even notice.
    Operations even during attack
    Acronis Disaster Recovery

    Servers are started directly from cloud backup. Available in minutes - not days.

    VPN connections are set up from the recovery environment to your offices.
    Vendors can log in directly to the recovery environment.
    Operations continue while you rebuild the environment in the background.
    Business Impact
    Time is critical.

    The difference between minutes and days of downtime.

    RTO
    Minutes
    Time to operation
    Back in operation
    File → VM
    From individual file to full server
    Platform
    In EU
    Geo-redundant cloud
    Test
    Test-failover
    Tested before the crisis arrives
    The entire stack

    That's why it works as a whole.

    Each layer sends signals. The MDR team connects them and acts 24/7. Together, the attacker has nowhere to hide.

    7 / 7
    Phases covered
    The entire attack chain in one system.
    1
    Console & agent
    No tool changes in the middle of a crisis.
    24/7
    Active response
    The MDR team sees everything and takes action.
    Minutes
    To operation
    Recovery environment from locked cloud backup.
    LayerAcronis productCapacityPhases covered
    EndpointAcronis XDRDetection, protection, behavioral telemetryPhase 2, 3, 4, 5
    Operations & incident responseAcronis RMMRemote management, patching, incident responsePhase 6
    Email & collaborationEmail & Collaboration SecurityStops phishing and malicious code in email and shared spacesPhase 1
    Back in operationBackup + Disaster RecoveryCloud backup, fast startup, VPN from recovery environmentPhase 5, 7
    Monitoring24/7 MDR IntegrationAlarm analysis and active 24/7 responseAll phases
    Key insights

    Six things to take away.

    1

    Secure the entry point

    Phishing is the most common entry. Email protection is non-negotiable.

    2

    Back in operation = reduced business impact

    Attackers use your own tools. Only behavioral analysis exposes them.

    3

    Data theft is the real threat

    Encryption is not the worst. Stolen data leads to GDPR fines and long-term reputational damage.

    Calculate the fines
    4

    Keep backups out of reach

    What they can't reach, they can't destroy. Locked cloud backups are your last lifeline.

    5

    One agent. Full overview.

    A unified platform gives your team the speed and overview needed to stop the attack.

    6

    Back in operation = business impact

    Every hour of downtime costs money. The recovery environment keeps you going while you rebuild your environment in the background.

    Free playbook
    Screenshot of the Akira ransomware group's terminal screen. Green monospace text on a black background with the AKIRA title in pixel art. The text reads: Well, you are here. It means that you're suffering from cyber incident right now. Think of our actions as an unscheduled forced audit of your network for vulnerabilities. Keep in mind that there is a fair price to make it all go away. Do not rush to assess what is happening - we did it to you. The best thing you can do is to follow our instructions to get back to your daily routine. Those who choose different path will be shamed here publicly. Remember. You are unable to recover without our help. Your data is already gone. Below is a command list: leaks, news, contact, help, clear.

    Run the same playbook our partners use at 03:14

    Step-by-step incident response built on the battle-tested stack. Free PDF, no fluff.

    Choose your region
    For MSPs & resellers

    Protect your customers with Gridheart × Acronis.

    A battle-tested stack from the Nordic's Acronis distributor. Up and running in minutes - not months.

    For end customers

    Do you want this stack in your business?

    Gridheart works through selected resellers. We'll connect you with a partner that suits your industry and size.