Akira is a financially motivated ransomware and extortion operation active since March 2023. Associated tracking names include PUNK SPIDER, GOLD SAHARA, Howling Scorpius, and Storm-1567. PUNK SPIDER identifies the adversary responsible for developing and maintaining Akira ransomware and its dedicated leak site, while GOLD SAHARA identifies activity involving Akira deployment. The operation includes core developers and intrusion affiliates operating under a ransomware-as-a-service model. Its victims span North America, Europe, Australia, and South America, including manufacturing, healthcare, education, financial services, telecommunications, construction, retail, hospitality, professional services, and government organizations. Akira typically employs double extortion, exfiltrating sensitive information before encrypting systems and threatening public disclosure if victims refuse payment. It has also conducted data-theft-only extortion. Its operators maintain a dedicated leak site and have published stolen financial records and customer information following unsuccessful negotiations. Payloads target Windows, Linux, and VMware ESXi environments and include C++-based Akira ransomware, Rust-based Megazord, and Akira_v2 variants. Akira uses hybrid ChaCha20 and RSA encryption and deletes volume shadow copies to impede recovery. Operators have also encrypted files remotely over SMB shares from unmanaged systems. Initial access commonly involves compromised VPN credentials, accounts without multifactor authentication, exposed remote services, spearphishing, and exploitation of perimeter vulnerabilities. Confirmed intrusion techniques include exploitation of Cisco ASA vulnerabilities CVE-2020-3259 and CVE-2023-20269. After entry, operators harvest credentials, escalate privileges, enumerate networks and domain relationships, create accounts for persistence, and move laterally through remote services such as RDP. Their toolkit includes Mimikatz, LaZagne, network scanners, legitimate remote-access applications, and Rclone, WinSCP, and FileZilla for exfiltration. Akira operators impair endpoint defenses, including through bring-your-own-vulnerable-driver attacks using PowerTool and a signed Zemana anti-malware driver to disable EDR at kernel level.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
19 CVEs this actor has used in observed campaigns. 19 of them exploited in the wild.
The author reports strong indications that Akira and Fog were exploiting CVE-2024-40766 for unauthorized access, with more than 100 suspected victim organizations as of December 23, 2024. However, the article explicitly states that exploitation had not been definitively established. At least 48,933 internet-exposed SonicWall devices reportedly remained unpatched as of December 24, 2024.
Akira has also been observed gaining initial access to their victims through VPN services without multifactor authentication (MFA) enabled, mostly using known Cisco vulnerabilities (CVE-2020-3259 and CVE-2023-20269).
Akira has also been observed gaining initial access to their victims through VPN services without multifactor authentication (MFA) enabled, mostly using known Cisco vulnerabilities (CVE-2020-3259 and CVE-2023-20269).
They also exploit CVE-2023-27532 in Veeam Backup & Replication to steal clear-text credentials stored in the backup server's configuration database.
Lateral Movement: Exploiting flaws such as CVE-2023-20269 (Cisco VPN) and CVE-2024-40711 (Veeam Backup & Replication).
14 more CVEs tied to this actor tracked in Mallory.
202 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Akira is identified as responsible for a ransomware attack against Yarema, a US-based metal fabrication and assembly company, discovered on October 9, 2026. The report includes a claim that 13 GB of corporate data will be published, including employee identity documents and Social Security information, projects, client information, and nondisclosure agreements. The content does not independently verify the claimed data theft.
Reportedly attacked TigerPress (DCC), a US print and packaging provider. The report attributes a claim to the group that it would publish 9 GB of corporate data, including employee and client personal information and project data. The incident was discovered on October 9, 2026; the content does not independently verify the claimed data theft.
Reportedly conducted a ransomware attack against Design Electric, an electrical contractor in St. Cloud, Minnesota. The attackers claim to possess 15 GB of corporate data and threaten to publish employee identity documents, Social Security numbers, contact details, project information, client information, and nondisclosure agreements. The report lists October 9, 2026 as both the breach and discovery date; the claimed data theft is not independently verified in the provided content.
Akira claims to have stolen 9 GB of corporate data from TigerPress (DCC), a US print and packaging provider, including employee and client personal information and project data. The post says the data will be uploaded "soon" but provides no specific deadline, ransom amount, or supporting samples.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.