Akira is a ransomware family and intrusion operation first observed in 2023 that targets enterprise environments and uses double extortion, stealing data before encrypting systems and threatening publication through a leak site and negotiation portal. It has affected organizations across multiple sectors, including manufacturing, construction, professional services, finance, education, consulting, healthcare, and agriculture, with activity heavily concentrated in North America and especially the United States, while also impacting victims in other regions.
Akira operators and affiliates commonly obtain initial access through exposed or vulnerable remote access infrastructure and public-facing network appliances, including SonicWall SSL VPN devices, Cisco ASA and FTD appliances, Fortinet appliances, and VMware vCenter, as well as through stolen credentials and, in some reporting, spearphishing or credential-marketplace access. Post-compromise activity includes credential theft, Active Directory enumeration, network scanning, creation of local and domain accounts, persistence via legitimate remote administration tools, lateral movement over RDP, SMB administrative shares, SSH, WMI, and remote execution frameworks, and staged data exfiltration using common file-transfer utilities.
The malware and associated tradecraft emphasize defense evasion. Akira intrusions have used Safe Mode with Networking to disrupt endpoint protection, attempted to disable Microsoft Defender and EDR products, abused vulnerable drivers or attacker-created virtual machines to bypass monitoring, deleted shadow copies, and in some cases targeted backup infrastructure such as Veeam or legacy backup services before encryption. Operators have also used hypervisor-focused techniques on VMware ESXi and Windows Hyper-V, including creating new virtual machines to evade endpoint controls and encrypt virtual machine storage.
On Windows, Akira encryptors have been described as multithreaded binaries that append a distinctive extension to encrypted files, drop a ransom note, delete shadow copies, and use partial encryption for speed. Public analyses have described use of ChaCha with RSA-protected key material in Windows samples. Linux variants target servers and network shares, including virtual machine, database, backup, and log files, and have been reported to use AES with RSA via the Nettle library. Akira has also operated Linux encryptors aimed at virtualization environments, particularly VMware ESXi.
Akira is associated with a ransomware-as-a-service style ecosystem or affiliate model rather than a single uniform intrusion pattern. Reporting has shown overlap in tooling and tradecraft with other ransomware actors and affiliates, including possible cross-program operator activity. The operation is notable for combining conventional enterprise ransomware behavior with adaptable intrusion methods against VPNs, virtualization infrastructure, and backup systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ASD’s ACSC is aware of a recent increase in active exploitation in Australia of a 2024 critical vulnerability in SonicWall SSL VPNs (CVE-2024-40766). We are aware of the Akira ransomware targeting vulnerable Australian organisations through SonicWall SSL VPNs. | We are aware of the Akira ransomware targeting vulnerable Australian organisations through SonicWall SSL VPNs.
During the first half of 2023... Akira affiliates get into the network by leveraging stolen passwords or by exploiting CVE-2023-20269 (Cisco ASA and FTD) vulnerability, allowing them to conduct brute-force attack on local password without being detected... In two cases, attackers exploited CVE-2023-20269 vulnerability on a Cisco ASA VPN appliance. This vulnerability allows an unauthenticated attacker to conduct a brute-force attack on any local account while bypassing the maximum number of attempts defined. | During the first half of 2023, CERT Intrinsec handled several incidents involving Akira ransomware group... Akira ransomware is said to have started operating in March 2023 and targeted more than 140 organisations.
The first of these tools was named decrypt.py ... and is used for decrypting password data from Fortinet devices vulnerable to CVE-2019-6693... Unlike decrypt.py, this tool chains CVE-2019-6693 and CVE-2022-40684 in order to increase the effectiveness of exploitation. | Stairwell researchers recovered a home directory that had been accidentally publicly exposed from a server conducting exploitation of Fortinet appliances and deploying the Akira ransomware.
The other tool identified for exploitation of Fortinet devices was named fortiConfParser.py ... This Python script is used for remotely extracting the configuration of Fortinet devices, using a publicly known authentication bypass (CVE-2022-40684) ... Unlike decrypt.py, this tool chains CVE-2019-6693 and CVE-2022-40684 in order to increase the effectiveness of exploitation. | Stairwell researchers recovered a home directory that had been accidentally publicly exposed from a server conducting exploitation of Fortinet appliances and deploying the Akira ransomware.
Once connected via the VPN, the threat actor leveraged a remote code execution (RCE) vulnerability (CVE-2021-21972) in the VMware vCenter server. This vulnerability affects the ‘uploadOVA’ function, allowing unauthenticated attackers to upload malicious files to the vulnerable ‘/ui/vropspluginui/rest/services/*’ endpoint. | In this special Cyber Intelligence Briefing, our cyber experts at S-RM, Ineta Simkunaite and Callum Wilson, unravel a recent encounter with the Akira ransomware group. Their review unveils a novel privilege escalation technique used by attackers.
Additional exploited vulnerabilities include ... CVE-2023-48788 (FortiClientEMS SQL injection) ... | Akira is a ransomware-as-a-service (RaaS) group that emerged in March 2023... Akira initially coded its ransomware in C++ for Windows... but introduced a new Rust-based variant in August 2023 (dubbed 'Megazord')... The group currently operates four primary variants: Akira, Megazord, Akira Linux, and Akira_v2.
and CVE-2020-3259, a memory disclosure vulnerability which can be used to retrieve credentials without authentication. | Unmasking Akira: the ransomware tactics you can’t afford to ignore... Akira focuses on being a double extortion group... first stealing data, then encrypting it, demanding payment to prevent public leaks and restore systems.
Akira have been observed to exploit Veeam vulnerabilities such as CVE-2023-27532 and CVE-2024-40711. | Unmasking Akira: the ransomware tactics you can’t afford to ignore... Akira focuses on being a double extortion group... first stealing data, then encrypting it, demanding payment to prevent public leaks and restore systems.
Akira have been observed to exploit Veeam vulnerabilities such as CVE-2023-27532 and CVE-2024-40711. | Unmasking Akira: the ransomware tactics you can’t afford to ignore... Akira focuses on being a double extortion group... first stealing data, then encrypting it, demanding payment to prevent public leaks and restore systems.
Additional exploited vulnerabilities include ... CVE-2024-37085 (VMware ESXi authentication bypass) ... | Akira is a ransomware-as-a-service (RaaS) group that emerged in March 2023... Akira initially coded its ransomware in C++ for Windows... but introduced a new Rust-based variant in August 2023 (dubbed 'Megazord')... The group currently operates four primary variants: Akira, Megazord, Akira Linux, and Akira_v2.
ReliaQuest identified what we assess with medium confidence to be the first known exploitation of this vulnerability, spanning multiple environments between February and March 2026... CVE-2024-12802 is an authentication bypass vulnerability in SonicWall appliances that reduces VPN security to single-factor authentication... On Gen6 devices, the firmware patch alone doesn’t remediate the vulnerability. Six additional manual reconfiguration steps are required.
In Q4 2023, Kroll identified an uptick in engagements involving Akira ransomware, a trend that has continued into 2024... Shortly after privilege escalation, Akira ransomware was deployed to encrypt systems.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In this special Cyber Intelligence Briefing, our cyber experts at S-RM, Ineta Simkunaite and Callum Wilson, unravel a recent encounter with the Akira ransomware group. Their review unveils a novel privilege escalation technique used by attackers.
Il s’agit du premier cas documenté par Huntress d’une intrusion Akira ransomware utilisant le mode sans échec Windows pour neutraliser les outils de détection endpoint.
The crown jewel of their operations is the use of the ransomware that gives them their name: Akira ... It retains various capabilities such as controlling disk drives, managing running processes, multi-threaded operation, and, of course, encrypting files and writing ransom notes on the victim’s devices.
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
In July 2024, Microsoft also linked the Storm-1175 threat group, along with three other cybercrime gangs, to Black Basta and Akira ransomware attacks that exploited a VMware ESXi authentication-bypass flaw.
"...the use of this technique has led to Akira and Black Basta ransomware deployments."
25 distinct techniques documented for this family, organized by ATT&CK tactic.
The vendor has also urged organisations to change passwords after updating to the latest version. Organisations remain vulnerable if they have not fully implemented the mitigation advice by updating credentials after updating the firmware.
An Akira ransomware affiliate broke into a company through an MFA-less SonicWall VPN... After gaining access via an exposed SonicWall VPN...
ASD’s ACSC is aware of a recent increase in active exploitation in Australia of a 2024 critical vulnerability in SonicWall SSL VPNs (CVE-2024-40766). We are aware of the Akira ransomware targeting vulnerable Australian organisations through SonicWall SSL VPNs.
The vendor has also urged organisations to change passwords after updating to the latest version. Organisations remain vulnerable if they have not fully implemented the mitigation advice by updating credentials after updating the firmware.
dumped all Active Directory users and computers with a PowerShell enumeration that disabled truncation to capture every group membership
Moreover, we have taken a great amount of your corporate data prior to encryption.
However, before encrypting files, the threat actors will steal corporate data for leverage in their extortion attempts, warning victims that it will be publicly released if a ransom is not paid.
all your backups - virtual, physical - everything that we managed to reach - are completely removed.
before launching the encryptor... The ransomware failed because Safe Mode limited available memory.
Akira also uses the Windows Restart Manager API to close processes or shut down Windows services that may be keeping a file open and preventing encryption.
313 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used by an Akira affiliate after VPN compromise. In this incident it was launched from Safe Mode with Networking to evade EDR, after credential theft, AD enumeration, file-share archiving, and data exfiltration. The encryptor failed due to out-of-virtual-memory errors in Safe Mode, but exfiltration still enabled extortion.
Ransomware operator concentrated in North America, known for repeatedly targeting SMBs via exposed or unpatched public-facing devices and focusing on construction, manufacturing, and professional services victims.
Ransomware group concentrated in North America, known for targeting SMBs via exposed or unpatched public-facing devices, especially in construction and manufacturing environments.
Ransomware described as rebooting infected Windows systems into Safe Mode in order to disable or evade EDR protections.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.