Akira is a financially motivated ransomware family first identified in March 2023. Initially targeting Windows, it expanded to Linux and VMware ESXi environments. Its operators employ double extortion, stealing sensitive information before encrypting files and threatening public disclosure unless victims pay. Targets include businesses and critical infrastructure across North America, Europe, Australia, and other regions, spanning manufacturing, healthcare, education, finance, professional services, and industrial services. PUNK SPIDER is associated with developing and maintaining Akira, while GOLD SAHARA is associated with its deployment.
Akira intrusions commonly begin through compromised VPN credentials, remote-access services without consistently enforced multifactor authentication, exposed RDP services, spearphishing, or exploitation of internet-facing appliances. Exploited vulnerabilities include CVE-2020-3259 and CVE-2023-20269 in Cisco ASA and Firepower Threat Defense, and CVE-2024-40766 in SonicWall appliances. Operators harvest credentials, discover internal systems, escalate privileges, move laterally through RDP, and maintain access using additional accounts, remote-access software, and tunneling tools. They stage and exfiltrate data using utilities including WinRAR, Rclone, WinSCP, and FileZilla.
Akira encryptors use hybrid ChaCha20 and RSA encryption, with variants supporting full or partial file encryption and targeting network shares or virtual machines. The original implementation was written in C++; subsequent payloads include the Rust-based Megazord and updated Windows, Linux, and ESXi encryptors. Attacks inhibit recovery by deleting volume shadow copies and impair security tools. Operators have used PowerTool to abuse a signed Zemana anti-malware driver for kernel-level EDR disabling through bring-your-own-vulnerable-driver techniques. In one documented incident, a compromised Linux-based webcam provided an alternative deployment point for ransomware against network shares after endpoint defenses blocked execution on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The threat actors have also been observed exploiting CVE-2020-3259, CVE-2023-20263, and CVE-2023-48788.
The threat actors have also been observed exploiting CVE-2020-3259, CVE-2023-20263, and CVE-2023-48788.
SonicWall waarschuwde vorige maand al voor het uitbuiten van de kwetsbaarheid (CVE-2024-40766) door de Akira-ransomware. Het bedrijf dichtte deze kwetsbaarheid in 2024 via een patch, maar deze update is nog altijd niet op alle getroffen firewalls geïnstalleerd.
Lateral Movement: Exploiting flaws such as CVE-2023-20269 (Cisco VPN) and CVE-2024-40711 (Veeam Backup & Replication).
The threat actors have also been observed exploiting CVE-2020-3259, CVE-2023-20263, and CVE-2023-48788.
They also exploit CVE-2023-27532 in Veeam Backup & Replication to steal clear-text credentials stored in the backup server's configuration database.
Lateral Movement: Exploiting flaws such as CVE-2023-20269 (Cisco VPN) and CVE-2024-40711 (Veeam Backup & Replication).
CVE-2022-40684 is a critical authentication bypass vulnerability in Fortinet FortiOS, FortiProxy, and FortiManager network edge appliances. With a CVSS score of 9.8, this vulnerability allows attackers to bypass authentication mechanisms completely, granting them administrator-level access to affected devices. | Threat groups like “Akira” have exploited CVE-2022-40684 for ransomware deployment.
Akira ransomware is a ransomware-as-a-service (RaaS) operation active since March 2023 that steals a victim’s data and then encrypts their systems to force payment.
The first of these tools was named decrypt.py ... and is used for decrypting password data from Fortinet devices vulnerable to CVE-2019-6693... Unlike decrypt.py, this tool chains CVE-2019-6693 and CVE-2022-40684 in order to increase the effectiveness of exploitation. | Stairwell researchers recovered a home directory that had been accidentally publicly exposed from a server conducting exploitation of Fortinet appliances and deploying the Akira ransomware.
Once connected via the VPN, the threat actor leveraged a remote code execution (RCE) vulnerability (CVE-2021-21972) in the VMware vCenter server. This vulnerability affects the ‘uploadOVA’ function, allowing unauthenticated attackers to upload malicious files to the vulnerable ‘/ui/vropspluginui/rest/services/*’ endpoint. | In this special Cyber Intelligence Briefing, our cyber experts at S-RM, Ineta Simkunaite and Callum Wilson, unravel a recent encounter with the Akira ransomware group. Their review unveils a novel privilege escalation technique used by attackers.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Several of the intrusions culminated in the deployment and execution of Akira or LockBit-related ransomware binaries.
Akira ransomware is a ransomware-as-a-service (RaaS) operation active since March 2023 that steals a victim’s data and then encrypts their systems to force payment.
Ransomware operators such as BlackByte, Storm-0506, Storm-1175, Octo Tempest, and Manatee Tempest have been actively exploiting CVE-2024-37085 ... where some of these cases have led to Akira and Black Basta ransomware deployments.
Ransomware operators such as BlackByte, Storm-0506, Storm-1175, Octo Tempest, and Manatee Tempest have been actively exploiting CVE-2024-37085 ... where some of these cases have led to Akira and Black Basta ransomware deployments.
Ransomware operators such as BlackByte, Storm-0506, Storm-1175, Octo Tempest, and Manatee Tempest have been actively exploiting CVE-2024-37085 ... where some of these cases have led to Akira and Black Basta ransomware deployments.
Ransomware operators such as BlackByte, Storm-0506, Storm-1175, Octo Tempest, and Manatee Tempest have been actively exploiting CVE-2024-37085 ... where some of these cases have led to Akira and Black Basta ransomware deployments.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Techniques to delete shadow copies and disable security tools to hinder recovery efforts will be used.
Akira threat actors encrypt data on target systems to interrupt availability to system and network resources.
371 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Encrypted the victim’s file shares. Investigators reconstructed repeated encryption activity using Shellbags, PowerShell events recording shadow-copy deletion, and Akira log files despite the absence of initial EDR telemetry.
Ransomware used to encrypt files in an organization's Shares folder. Investigators reconstructed repeated encryption activity by correlating Akira log files, Shellbags artifacts, and concurrent PowerShell commands deleting volume shadow copies. Limited pre-installation EDR telemetry prevented a complete reconstruction of initial access and earlier attacker activity.
Double-extortion ransomware that steals data and encrypts Windows, Linux, and virtualized environments, including VMware ESXi, Hyper-V, and Nutanix AHV. Affiliates commonly enter through compromised VPN credentials or exploited edge devices, steal credentials, disable defenses, undermine backups, and encrypt systems. The article reports ChaCha20 file encryption with RSA-4096-protected keys and the .akira extension. Attribution to a specific country remains unconfirmed.
Ransomware that encrypts files and appends the .akira extension. The article describes Windows and Linux versions, reported code overlaps with Ryuk, and an associated data leak site. Researchers attributed declining activity to its unsuccessful participation in a Royal-organized malware competition. Avast released a free decryptor in late June 2023, but the article cautions that Akira's demise remained uncertain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.