Skip to content

Akira

Akira is a ransomware operation active since March 2023 that conducts double-extortion attacks against corporate networks.

Profile source: Mallory opens in a new tab

Akira

Family profile

Akira is a ransomware operation active since March 2023 that conducts double-extortion attacks against corporate networks. Its affiliates have targeted organizations worldwide, with substantial activity against U.S. organizations across sectors including manufacturing, construction, technology, finance, education, real estate, consulting, and healthcare. Akira operators obtain access through compromised credentials used with VPN or remote desktop services and through exploitation of vulnerable internet-facing appliances, including Cisco and SonicWall VPN devices. Observed intrusions include credential spraying, Active Directory and network discovery, lateral movement via RDP and SMB administrative shares, creation of local or domain accounts, and deployment of legitimate remote-management tools for persistence and remote access. Before encryption, affiliates archive and exfiltrate corporate data and may target backup infrastructure, delete shadow copies, inhibit recovery, and disable endpoint defenses. The Windows encryptor terminates processes and services that impede encryption, encrypts a broad range of business, database, virtual-machine, disk-image, and backup-related files, and leaves ransom instructions directing victims to a negotiation portal. Akira uses stolen-data publication as leverage even where encryption or recovery disruption is unsuccessful.

Capabilities

  • Brute Force
  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Lateral Movement
  • Persistence
  • Reconnaissance
  • Scanning

Observed infrastructure

Last seven days

First activity
Sep 9, 2026
Last activity
Sep 9, 2026
Feed role
Distribution
Host form
1 IP / 0 hostnames

Leading locations

  • US1

Leading providers

  • Interserver, Inc1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

8 named in public reporting
Akira

A potential undisclosed zero-day vulnerability in SonicWall Gen 7 firewall appliances is believed to be exploited by threat actors, leading to the deployment of Akira ransomware.

UNC5221

In this special Cyber Intelligence Briefing, our cyber experts at S-RM, Ineta Simkunaite and Callum Wilson, unravel a recent encounter with the Akira ransomware group. Their review unveils a novel privilege escalation technique used by attackers.

WIZARD SPIDER

The crown jewel of their operations is the use of the ransomware that gives them their name: Akira ... It retains various capabilities such as controlling disk drives, managing running processes, multi-threaded operation, and, of course, encrypting files and writing ransom notes on the victim’s devices.

Scattered Spider

These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)

Storm-1175

In July 2024, Microsoft also linked the Storm-1175 threat group, along with three other cybercrime gangs, to Black Basta and Akira ransomware attacks that exploited a VMware ESXi authentication-bypass flaw.

Storm-0506

"...the use of this technique has led to Akira and Black Basta ransomware deployments."

INDRIK SPIDER

"...the use of this technique has led to Akira and Black Basta ransomware deployments."

Conti

In 2024, the top 3 ransomware threats to Canada were: Akira... emerged in April 2023... operates 2 ransomware variants... exfiltrates victim data before encrypting... double extortion.

Exploited software

Vulnerabilities linked to Akira

25 CVEs
CVE-2024-40766 Improper Access Control in SonicWall SonicOS Management Access and SSLVPN CVE-2023-20269 Unauthorized Access and Brute-Force Exposure in Cisco ASA and FTD Remote Access VPN CVE-2019-6693 Hard-coded Cryptographic Key in FortiOS Configuration Backups CVE-2022-40684 Authentication Bypass in Fortinet FortiOS, FortiProxy, and FortiSwitchManager Administrative Interface CVE-2021-21972 VMware vCenter Server vROPS Client Plugin Unauthenticated RCE CVE-2023-48788 Fortinet FortiClient EMS DB2 Administration Server SQL Injection RCE CVE-2020-3259 Information Disclosure in Cisco ASA and Cisco FTD Web Services Interface CVE-2023-27532 Unauthenticated Credential Disclosure in Veeam Backup & Replication CVE-2024-40711 Unauthenticated RCE in Veeam Backup & Replication CVE-2024-37085 Authentication Bypass in VMware ESXi Active Directory Integration CVE-2024-12802 MFA Bypass in SonicWall SSL-VPN Active Directory Authentication CVE-2023-20263 Open Redirect in Cisco HyperFlex HX Data Platform Web Management Interface CVE-2023-48365 DoubleQlik: Unauthenticated RCE in Qlik Sense Enterprise for Windows CVE-2025-23006 SonicWall SMA1000 AMC/CMC Pre-Authentication Deserialization RCE CVE-2024-21762 Fortinet FortiOS and FortiProxy SSL-VPN Out-of-Bounds Write RCE CVE-2023-27997 XORtigate CVE-2025-55182 React2Shell CVE-2025-23120 Remote Code Execution in Veeam Backup & Replication CVE-2025-7771 Arbitrary Physical Memory Read/Write in TechPowerUp ThrottleStop.sys CVE-2024-53704 SonicWall SonicOS SSLVPN Authentication Bypass CVE-2023-28252 Windows CLFS Driver Out-of-Bounds Write Elevation of Privilege CVE-2020-3580 Cross-Site Scripting in Cisco ASA and Firepower FTD Web Services Interface CVE-2025-59287 Unauthenticated RCE in Windows Server Update Services CVE-2021-20028 SQL Injection in SonicWall Secure Remote Access (SRA) Appliances CVE-2019-7481 SQL Injection in SonicWall SMA100

MITRE ATT&CK

Akira in ATT&CK

77 distinct techniques

Techniques

77 techniques
T1213 Data from Information Repositories T1486 Data Encrypted for Impact T1567 Exfiltration Over Web Service T1005 Data from Local System T1657 Financial Theft T1041 Exfiltration Over C2 Channel T1136 Create Account T1090 Proxy T1016 System Network Configuration Discovery T1098 Account Manipulation T1482 Domain Trust Discovery T1047 Windows Management Instrumentation T1555 Credentials from Password Stores T1562 Impair Defenses T1021 Remote Services T1560 Archive Collected Data T1219 Remote Access Tools T1046 Network Service Discovery T1078 Valid Accounts T1003 OS Credential Dumping T1070.004 File Deletion T1059.001 PowerShell T1190 Exploit Public-Facing Application T1105 Ingress Tool Transfer T1048 Exfiltration Over Alternative Protocol T1111 Multi-Factor Authentication Interception T1033 System Owner/User Discovery T1110.003 Password Spraying T1567.002 Exfiltration to Cloud Storage T1133 External Remote Services T1112 Modify Registry T1087 Account Discovery T1021.001 Remote Desktop Protocol T1562.009 Safe Mode Boot T1537 Transfer Data to Cloud Account T1489 Service Stop T1490 Inhibit System Recovery T1106 Native API T1135 Network Share Discovery T1485 Data Destruction T1562.001 Disable or Modify Tools T1529 System Shutdown/Reboot T1018 Remote System Discovery T1059 Command and Scripting Interpreter T1547.001 Registry Run Keys / Startup Folder T1074 Data Staged T1098.004 SSH Authorized Keys T1110 Brute Force T1210 Exploitation of Remote Services T1003.003 NTDS T1562.004 Disable or Modify System Firewall T1020 Automated Exfiltration T1082 System Information Discovery T1484.001 Group Policy Modification T1569.002 Service Execution T1036 Masquerading T1083 File and Directory Discovery T1057 Process Discovery T1027 Obfuscated Files or Information T1570 Lateral Tool Transfer T1608.006 SEO Poisoning T1583 Acquire Infrastructure T1021.002 SMB/Windows Admin Shares T1584.006 Web Services T1003.001 LSASS Memory T1053.005 Scheduled Task T1572 Protocol Tunneling T1569 System Services T1560.001 Archive via Utility T1587.001 Malware T1553.002 Code Signing T1059.003 Windows Command Shell T1566 Phishing T1543.003 Windows Service T1552 Unsecured Credentials T1565 Data Manipulation T1068 Exploitation for Privilege Escalation

Reporting

Research mentioning Akira

Aug 26
Zdnet Zero Day

July was the worst month for ransomware victim claims in 2026 - or was it? | ZDNET

Security reporting has documented LameHug as the first publicly known malware to integrate a large language model, marking an escalation in the use of generative AI within malicious tooling. The development indicates that AI can be incorporated into malware operations rather than being used solely to create phishing content or assist attackers outside the payload. Separately, ransomware victim listings reached 894 organizations in July 2026, according to NCC Group data cited by ZDNET, with industrial organizations comprising nearly one-third of listed victims. The reporting also identified the first documented fully agentic AI ransomware attack chain, attributed to JadePuffer, amid a surge led by groups including The Gentlemen and Qilin; however, organizations should treat leak-site claims cautiously because some actors, including the new CRPxO RaaS operation, may inflate or fabricate victim listings.

Aug 20
Hookphish

Ransomware Group qilin Hits: Trends And Concepts

Researchers reported that the Agenda ransomware operation, also tracked as Qilin, is conducting highly customized enterprise attacks across Asia and Africa and has now been linked to a victim in South Africa. A recent victim listing identified Trends And Concepts in South Africa, associated with the domain www.trendsandconceptsinteriors.com, as impacted by the Qilin group. Trend researchers said Agenda operators build victim-specific Go-based payloads that can include leaked account credentials, unique company identifiers, customized RSA keys, and ransom demands ranging from $50,000 to $800,000, with observed targeting of healthcare and education organizations in Indonesia, Saudi Arabia, South Africa, and Thailand. The intrusion methods described across the reports show a flexible and increasingly sophisticated playbook. In one case, attackers accessed a public-facing Citrix server using a valid account, moved laterally with RDP and leaked Active Directory credentials, scanned networks with Nmap and Nping, and deployed ransomware through Group Policy in under two days. A separate Trend investigation found Agenda actors using fake Google CAPTCHA pages to deliver credential stealers, then abusing legitimate remote-management tools including ATERA, AnyDesk, ScreenConnect, and Splashtop, while deploying COROXY SOCKS proxies, targeting Veeam backup infrastructure, and using BYOVD techniques with vulnerable drivers such as eskle.sys; the final ransomware payload was reportedly a Linux variant executed on Windows, likely through Windows Subsystem for Linux.

Aug 19
Trendai Security

Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques | TrendAI (US)

Aug 14
Trendai Security

New Golang Ransomware Agenda Customizes Attacks | TrendAI (US)

Aug 12
Register Security

Akira ransomware scum blocked victim's security tools - and broke their own encryptor

An Akira ransomware affiliate breached a victim through a SonicWall SSL VPN account that lacked MFA after a credential-spraying attempt, then used RDP and Active Directory enumeration to map the environment, collect data, and stage exfiltration. Huntress reported the attacker created AdUsers.txt and AdComp.txt with PowerShell-based AD dumps, used WinRAR to package files, s5cmd to move data to S3, and installed AnyDesk for persistent remote access and payload delivery before launching the Akira encryptor. The intrusion’s notable defense-evasion step was forcing a compromised Windows host to reboot into Safe Mode with Networking, a technique tracked by MITRE ATT&CK as T1688, to disable endpoint protections while preserving connectivity. In Safe Mode, the Huntress agent and Microsoft Defender real-time protection were suppressed, but the Akira encryptor appears to have hit virtual-memory errors and failed to complete encryption; Defender later detected akira.exe yet could not quarantine it until the system returned to normal mode. Researchers warned the failure was accidental rather than protective, and urged organizations to enforce MFA on VPN access and monitor for failed VPN login bursts, Safe Mode boot changes, and unexpected security-service stoppages.

Aug 12
Huntress

Akira Hits Safe Mode: Ransomware Rebooting Around EDR | Huntress

Jul 22
Belgium Ccb News

Threat Intelligence Report: Qilin (Agenda) Ransomware | CCB Belgium

Qilin ransomware has emerged as one of the most active cybercrime threats, with NCC Group identifying it as the most prolific ransomware group for the fifth consecutive quarter as global ransomware incidents climbed to 2,229 in Q2 2026. The group, also tracked as Agenda or Qilin Locker, operates a double-extortion RaaS model and has concentrated on high-GDP Western countries while reportedly avoiding CIS member states. Manufacturing and other industrial sectors have been hit hardest, alongside business services, technology, healthcare, and finance, with North America remaining the most affected region and Belgium reporting at least 15 alleged Qilin compromises that disrupted operations and exposed sensitive corporate data.

Jul 22
Itsecurityguru

Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns - IT Security Guru

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.