US government agencies are warning that the Akira ransomware operation has been spotted encrypting Nutanix AHV virtual machines in attacks. An updated joint advisory from CISA, the FBI, the Department of Defense Cyber Crime Center (DC3), the Department of Health and Human Services (HHS), and several international partners alerts that Akira ransomware has expanded its encryption capabilities Nutanix AHV VM disk files. The advisory includes new indicators of compromise and tactics observed through FBI investigations and third-party reporting as recent as November 2025. The advisory warns that in June 2025 Akira actors started to encrypt disk files for Nutanix AHV virtual machines. "In a June 2025 incident, Akira threat actors encrypted Nutanix AHV VM disk files for the first time, expanding their capabilities beyond VMware ESXi and Hyper-V by abusing Common Vulnerabilities and Exposures (CVE)-2024-40766 [Common Weakness Enumeration (CWE)-284: Improper Access Control], a SonicWall vulnerability," reads the updated advisory. Nutanix's AHV platform is a Linux-based virtualization solution that runs and manages virtual machines on Nutanix's infrastructure. As it is widely deployed, it is no surprise that ransomware gangs would begin to target virtual machines on this platform, as they do with VMware ESXi and Hyper-V. While CISA has not shared how Akira is targeting Nutanix AHV environments, Akira Linux encryptors analyzed by BleepingComputer attempt to encrypt files with the .qcow...
CISA warns of Akira ransomware Linux encryptor targeting Nutanix VMs
BleepingComputer
·Lawrence Abrams
·Published Nov 13, 2025
·Updated
Affected Software
2 affected components
SonicWall SonicWall
Nutanix Ahv
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the warning issued by CISA regarding the Akira ransomware encrypting Nutanix virtual machines.
2
What security implications are discussed in this article?
The article highlights the risk posed by the Akira ransomware operation targeting critical infrastructure through Nutanix AHV virtual machines.
3
What products or software are affected by the Akira ransomware?
The affected software includes Nutanix AHV and potentially SonicWall products.
4
What organizations are involved in issuing the warning?
The warning is issued by CISA, the FBI, and the Department of Defense Cyber Crime Center.
5
What actions are recommended to mitigate the Akira ransomware threat?
While the article does not specify actions, it generally calls for heightened vigilance and cybersecurity practices to protect against ransomware attacks.