home.social

#akira — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #akira, aggregated by home.social.

  1. The revitalized #DirectorsVillage isn't officially open yet, but we were treated to an advance 4K screening of #Akira (which I've never seen on the big screen). Kodansha manga editor Takeshi Katsurada joined us in person to introduce the iconic anime to a packed house before watching it with us! #letterboxdfriday #LastFourWatched 🪓🤠🏍️🛗 #cinemastodon

  2. took the kid to see #akira on the big screen. ruled.

    #anime

  3. Node.js: Old Technique Makes a Comeback

    A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels. Attackers leverage the legitimate, signed node.exe binary to execute malicious JavaScript payloads, evading signature-based detection. In one intrusion at an Asian technology company, attackers downloaded the official Node.js installer after repeated payload blocks and used it to run an implant communicating with Ethereum blockchain gateways via EtherHiding techniques. The same threat actors compromised a U.S. fintech firm, deploying the Rust-based C2Looper backdoor linked to ransomware operations. Multiple attacks involved ModeloRAT, associated with initial access broker Woodgnat, connected to ransomware families including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo. Attackers employ ClickFix techniques for initial access and combine living-off-the-land tools with commodity malware.

    Pulse ID: 6a996ed3562f794a642feaaf
    Pulse Link: otx.alienvault.com/pulse/6a996
    Pulse Author: AlienVault
    Created: 2026-09-03 12:57:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #8Base #Akira #Asia #BackDoor #BlackBasta #BlockChain #CyberSecurity #EtherHiding #Government #InfoSec #Java #JavaScript #Malware #Nodejs #OTX #OpenThreatExchange #RAT #RansomWare #Rhysida #Rust #bot #AlienVault

  4. Node.js: Old Technique Makes a Comeback

    A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels. Attackers leverage the legitimate, signed node.exe binary to execute malicious JavaScript payloads, evading signature-based detection. In one intrusion at an Asian technology company, attackers downloaded the official Node.js installer after repeated payload blocks and used it to run an implant communicating with Ethereum blockchain gateways via EtherHiding techniques. The same threat actors compromised a U.S. fintech firm, deploying the Rust-based C2Looper backdoor linked to ransomware operations. Multiple attacks involved ModeloRAT, associated with initial access broker Woodgnat, connected to ransomware families including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo. Attackers employ ClickFix techniques for initial access and combine living-off-the-land tools with commodity malware.

    Pulse ID: 6a996ed3562f794a642feaaf
    Pulse Link: otx.alienvault.com/pulse/6a996
    Pulse Author: AlienVault
    Created: 2026-09-03 12:57:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #8Base #Akira #Asia #BackDoor #BlackBasta #BlockChain #CyberSecurity #EtherHiding #Government #InfoSec #Java #JavaScript #Malware #Nodejs #OTX #OpenThreatExchange #RAT #RansomWare #Rhysida #Rust #bot #AlienVault

  5. Node.js: Old Technique Makes a Comeback

    A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels. Attackers leverage the legitimate, signed node.exe binary to execute malicious JavaScript payloads, evading signature-based detection. In one intrusion at an Asian technology company, attackers downloaded the official Node.js installer after repeated payload blocks and used it to run an implant communicating with Ethereum blockchain gateways via EtherHiding techniques. The same threat actors compromised a U.S. fintech firm, deploying the Rust-based C2Looper backdoor linked to ransomware operations. Multiple attacks involved ModeloRAT, associated with initial access broker Woodgnat, connected to ransomware families including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo. Attackers employ ClickFix techniques for initial access and combine living-off-the-land tools with commodity malware.

    Pulse ID: 6a996ed3562f794a642feaaf
    Pulse Link: otx.alienvault.com/pulse/6a996
    Pulse Author: AlienVault
    Created: 2026-09-03 12:57:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #8Base #Akira #Asia #BackDoor #BlackBasta #BlockChain #CyberSecurity #EtherHiding #Government #InfoSec #Java #JavaScript #Malware #Nodejs #OTX #OpenThreatExchange #RAT #RansomWare #Rhysida #Rust #bot #AlienVault

  6. Node.js: Old Technique Makes a Comeback

    A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels. Attackers leverage the legitimate, signed node.exe binary to execute malicious JavaScript payloads, evading signature-based detection. In one intrusion at an Asian technology company, attackers downloaded the official Node.js installer after repeated payload blocks and used it to run an implant communicating with Ethereum blockchain gateways via EtherHiding techniques. The same threat actors compromised a U.S. fintech firm, deploying the Rust-based C2Looper backdoor linked to ransomware operations. Multiple attacks involved ModeloRAT, associated with initial access broker Woodgnat, connected to ransomware families including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo. Attackers employ ClickFix techniques for initial access and combine living-off-the-land tools with commodity malware.

    Pulse ID: 6a996ed3562f794a642feaaf
    Pulse Link: otx.alienvault.com/pulse/6a996
    Pulse Author: AlienVault
    Created: 2026-09-03 12:57:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #8Base #Akira #Asia #BackDoor #BlackBasta #BlockChain #CyberSecurity #EtherHiding #Government #InfoSec #Java #JavaScript #Malware #Nodejs #OTX #OpenThreatExchange #RAT #RansomWare #Rhysida #Rust #bot #AlienVault

  7. Node.js: Old Technique Makes a Comeback

    A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels. Attackers leverage the legitimate, signed node.exe binary to execute malicious JavaScript payloads, evading signature-based detection. In one intrusion at an Asian technology company, attackers downloaded the official Node.js installer after repeated payload blocks and used it to run an implant communicating with Ethereum blockchain gateways via EtherHiding techniques. The same threat actors compromised a U.S. fintech firm, deploying the Rust-based C2Looper backdoor linked to ransomware operations. Multiple attacks involved ModeloRAT, associated with initial access broker Woodgnat, connected to ransomware families including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo. Attackers employ ClickFix techniques for initial access and combine living-off-the-land tools with commodity malware.

    Pulse ID: 6a996ed3562f794a642feaaf
    Pulse Link: otx.alienvault.com/pulse/6a996
    Pulse Author: AlienVault
    Created: 2026-09-03 12:57:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #8Base #Akira #Asia #BackDoor #BlackBasta #BlockChain #CyberSecurity #EtherHiding #Government #InfoSec #Java #JavaScript #Malware #Nodejs #OTX #OpenThreatExchange #RAT #RansomWare #Rhysida #Rust #bot #AlienVault

  8. Hits Safe Mode: Ransomware Rebooting Around EDR

    An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.

    Pulse ID: 6a7ca262c4921e41ead16a57
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault