Akira ransomware is now targeting Nutanix VMs – and reaping big rewards


  • Akira now encrypts Nutanix AHV VM disk files using SonicWall and Veeam vulnerabilities
  • CVE-2024-40766 enabled access to firewalls; Akira used remote tools for lateral movement
  • Akira has extorted over $240 million; users are encouraged to patch and enforce MFA

The Akira ransomware operation is now also targeting Nutanix AHV VM disk files and is seeing great success, an updated security advisory released by the US Cybersecurity and Infrastructure Security Agency (CISA), the Department of Defense Cyber ​​Crime Center (DC3) and other agencies has said.

The update says Akira was observed encrypting Nutanix AHV VM disk files for the first time, in June 2025.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top