Last seven days
- First activity
- Sep 9, 2026
- Last activity
- Sep 9, 2026
- Feed role
- Distribution
- Host form
- 1 IP / 0 hostnames
Akira is a ransomware operation active since March 2023 that conducts double-extortion attacks against corporate networks.
Profile source: Mallory opens in a new tabAkira
Akira is a ransomware operation active since March 2023 that conducts double-extortion attacks against corporate networks. Its affiliates have targeted organizations worldwide, with substantial activity against U.S. organizations across sectors including manufacturing, construction, technology, finance, education, real estate, consulting, and healthcare. Akira operators obtain access through compromised credentials used with VPN or remote desktop services and through exploitation of vulnerable internet-facing appliances, including Cisco and SonicWall VPN devices. Observed intrusions include credential spraying, Active Directory and network discovery, lateral movement via RDP and SMB administrative shares, creation of local or domain accounts, and deployment of legitimate remote-management tools for persistence and remote access. Before encryption, affiliates archive and exfiltrate corporate data and may target backup infrastructure, delete shadow copies, inhibit recovery, and disable endpoint defenses. The Windows encryptor terminates processes and services that impede encryption, encrypts a broad range of business, database, virtual-machine, disk-image, and backup-related files, and leaves ransom instructions directing victims to a negotiation portal. Akira uses stolen-data publication as leverage even where encryption or recovery disruption is unsuccessful.
Samples
Reported operators
A potential undisclosed zero-day vulnerability in SonicWall Gen 7 firewall appliances is believed to be exploited by threat actors, leading to the deployment of Akira ransomware.
In this special Cyber Intelligence Briefing, our cyber experts at S-RM, Ineta Simkunaite and Callum Wilson, unravel a recent encounter with the Akira ransomware group. Their review unveils a novel privilege escalation technique used by attackers.
The crown jewel of their operations is the use of the ransomware that gives them their name: Akira ... It retains various capabilities such as controlling disk drives, managing running processes, multi-threaded operation, and, of course, encrypting files and writing ransom notes on the victim’s devices.
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
In July 2024, Microsoft also linked the Storm-1175 threat group, along with three other cybercrime gangs, to Black Basta and Akira ransomware attacks that exploited a VMware ESXi authentication-bypass flaw.
"...the use of this technique has led to Akira and Black Basta ransomware deployments."
"...the use of this technique has led to Akira and Black Basta ransomware deployments."
In 2024, the top 3 ransomware threats to Canada were: Akira... emerged in April 2023... operates 2 ransomware variants... exfiltrates victim data before encrypting... double extortion.
Exploited software
MITRE ATT&CK
Reporting
Security reporting has documented LameHug as the first publicly known malware to integrate a large language model, marking an escalation in the use of generative AI within malicious tooling. The development indicates that AI can be incorporated into malware operations rather than being used solely to create phishing content or assist attackers outside the payload. Separately, ransomware victim listings reached 894 organizations in July 2026, according to NCC Group data cited by ZDNET, with industrial organizations comprising nearly one-third of listed victims. The reporting also identified the first documented fully agentic AI ransomware attack chain, attributed to JadePuffer, amid a surge led by groups including The Gentlemen and Qilin; however, organizations should treat leak-site claims cautiously because some actors, including the new CRPxO RaaS operation, may inflate or fabricate victim listings.
Researchers reported that the Agenda ransomware operation, also tracked as Qilin, is conducting highly customized enterprise attacks across Asia and Africa and has now been linked to a victim in South Africa. A recent victim listing identified Trends And Concepts in South Africa, associated with the domain www.trendsandconceptsinteriors.com, as impacted by the Qilin group. Trend researchers said Agenda operators build victim-specific Go-based payloads that can include leaked account credentials, unique company identifiers, customized RSA keys, and ransom demands ranging from $50,000 to $800,000, with observed targeting of healthcare and education organizations in Indonesia, Saudi Arabia, South Africa, and Thailand. The intrusion methods described across the reports show a flexible and increasingly sophisticated playbook. In one case, attackers accessed a public-facing Citrix server using a valid account, moved laterally with RDP and leaked Active Directory credentials, scanned networks with Nmap and Nping, and deployed ransomware through Group Policy in under two days. A separate Trend investigation found Agenda actors using fake Google CAPTCHA pages to deliver credential stealers, then abusing legitimate remote-management tools including ATERA, AnyDesk, ScreenConnect, and Splashtop, while deploying COROXY SOCKS proxies, targeting Veeam backup infrastructure, and using BYOVD techniques with vulnerable drivers such as eskle.sys; the final ransomware payload was reportedly a Linux variant executed on Windows, likely through Windows Subsystem for Linux.
An Akira ransomware affiliate breached a victim through a SonicWall SSL VPN account that lacked MFA after a credential-spraying attempt, then used RDP and Active Directory enumeration to map the environment, collect data, and stage exfiltration. Huntress reported the attacker created AdUsers.txt and AdComp.txt with PowerShell-based AD dumps, used WinRAR to package files, s5cmd to move data to S3, and installed AnyDesk for persistent remote access and payload delivery before launching the Akira encryptor. The intrusion’s notable defense-evasion step was forcing a compromised Windows host to reboot into Safe Mode with Networking, a technique tracked by MITRE ATT&CK as T1688, to disable endpoint protections while preserving connectivity. In Safe Mode, the Huntress agent and Microsoft Defender real-time protection were suppressed, but the Akira encryptor appears to have hit virtual-memory errors and failed to complete encryption; Defender later detected akira.exe yet could not quarantine it until the system returned to normal mode. Researchers warned the failure was accidental rather than protective, and urged organizations to enforce MFA on VPN access and monitor for failed VPN login bursts, Safe Mode boot changes, and unexpected security-service stoppages.
Qilin ransomware has emerged as one of the most active cybercrime threats, with NCC Group identifying it as the most prolific ransomware group for the fifth consecutive quarter as global ransomware incidents climbed to 2,229 in Q2 2026. The group, also tracked as Agenda or Qilin Locker, operates a double-extortion RaaS model and has concentrated on high-GDP Western countries while reportedly avoiding CIS member states. Manufacturing and other industrial sectors have been hit hardest, alongside business services, technology, healthcare, and finance, with North America remaining the most affected region and Belgium reporting at least 15 alleged Qilin compromises that disrupted operations and exposed sensitive corporate data.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.