Megazord is a Rust-based ransomware encryptor targeting Windows systems, deployed in Akira ransomware attacks beginning in August 2023. It encrypts victim files for financial extortion. Akira operators have used Megazord alongside or interchangeably with other Akira encryptors, including deploying Windows-specific Megazord and the separate Akira_v2 ESXi encryptor during the same compromise.
Megazord is associated with the Akira operation, whose threat-actor designations include PUNK SPIDER and GOLD SAHARA. The operation uses double extortion, stealing sensitive information before encrypting systems and threatening publication to pressure victims into paying. These intrusions commonly begin through compromised VPN credentials, vulnerable remote-access infrastructure, exposed RDP services, or spearphishing; these are operator access methods rather than capabilities of the Megazord encryptor itself. Akira campaigns have affected businesses and critical infrastructure across North America, Europe, and Australia, including organizations in manufacturing, education, healthcare, financial services, and information technology.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Beginning in August 2023, some Akira attacks began deploying Megazord, using Rust-based code which encrypts files with a .powerranges extension.”
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Akira predominantly gains access through compromised VPN credentials lacking multi-factor authentication... Secondary access methods include ... purchasing access from initial access brokers.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rust-based ransomware variant used in Akira attacks from August 2023. It appends the .powerranges extension to encrypted files.
Megazord is a ransomware family identified by unique YARA signatures. It is related to the win.akira family detection.
Rust-based, Windows-specific ransomware deployed in Akira operations. It appends .powerranges to encrypted files and has been deployed alongside the Akira_v2 ESXi encryptor within the same compromise.
Ransomware encryptor/tooling observed deployed alongside Akira_v2 (noted as previously used targeting Windows environments), and assessed in the content as potentially fading out as Akira consolidates tooling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.