Skip to content

Akira

Akira is a ransomware operation active since March 2023 that conducts double-extortion attacks against corporate networks.

Profile source: Mallory opens in a new tab

Akira

Family profile

Akira is a ransomware operation active since March 2023 that conducts double-extortion attacks against corporate networks. Affiliates have gained access through compromised VPN credentials, exposed remote-access services, exploitation of known vulnerabilities in perimeter appliances, and credential attacks. Observed intrusions include discovery and Active Directory enumeration, creation of local and domain accounts, use of legitimate remote-management tools, lateral movement over RDP and SMB administrative shares, and theft of corporate data before encryption. Akira operators have targeted backup infrastructure and recovery mechanisms, including Veeam environments and Volume Shadow Copies, and have attempted to disable endpoint security controls; one observed affiliate used Safe Mode with Networking to impair EDR protections. The ransomware encrypts a broad range of business, database, virtual-machine, disk-image, and backup-related data while avoiding selected operating-system and executable files. It can use the Windows Restart Manager API to stop processes and services that obstruct encryption. Akira uses a leak site and Tor-based negotiation portal to pressure victims with threatened publication or sale of stolen data. Victims span numerous sectors, including construction, manufacturing, education, finance, real estate, consulting, technology, healthcare, and professional services, with substantial activity reported against organizations in the United States and North America.

Capabilities

  • Brute Force
  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Lateral Movement
  • Persistence
  • Privilege Escalation
  • Reconnaissance
  • Scanning

Operational record

365
Indicators
1
YARA rules
3
Ransom notes
76
Negotiations
2
Leak sites
2 available

Credential Theft

  • DonPAPI
  • LaZagne
  • Mimikatz

Defense Evasion

  • PowerTool
  • ThrottleStop driver
  • Zemana Anti-Rootkit driver
  • churchill_driver.sys / fidget.sys
  • consent.exe (msimg32.dll / wmsgapi.dll)
  • icardagt.exe (version.dll DLL sideload)
  • mfpmp.exe (rtworkq.dll DLL sideload)

Discovery Enum

  • Advanced IP Scanner
  • Advanced Port Scanner
  • Bloodhound
  • Masscan
  • ReconFTW
  • ShareFinder
  • SharpHound
  • SharpShares
  • SoftPerfect NetScan
  • ldapdomaindump

Exfiltration

  • FileZilla
  • MEGA
  • RClone
  • Temp[.]sh
  • WinRAR
  • WinSCP

LOLBAS

  • net
  • netsh
  • nltest
  • vssadmin

Networking

  • Cloudflared
  • Ngrok
  • OpenSSH

Offsec

  • CrackMapExec
  • Impacket
  • NetExec

RMM Tools

  • AnyDesk
  • MeshAgent
  • MobaXterm
  • Radmin
  • RustDesk
  • TeamViewer

Published indicators

Md5

320 total
  • 083740c55d0a459674457b8551ed9c6a
  • 1a7df536c3bb676a6f90af5b3bea5302
  • 4d43e35962c8c7fdca5f64da8f561f5a
  • f17b6cdcbac9462f01da65bd4f8636db
  • 27182f9017d8e4212fbc32e954e19d37
  • ab359be0ab33876eb32325706e43f0c1
  • 1d895cf4391b817e54fb9ec9d8e65f7e
  • 03b9887dee2c3c825b6a6c0df1d104ad
  • 4d79fb750955ec8702cb79cfdb36e66b
  • c387b2eb96bb137cdd54220d920edce9

Sha256

37 total
  • 78d75669390e4177597faf9271ce3ad3a16a3652e145913dbfa9a5951972fcb0
  • 2c7aeac07ce7f03b74952e0e243bd52f2bfa60fadc92dd71a6a1fee2d14cdd77
  • 88da2b1cee373d5f11949c1ade22af0badf16591a871978a9e02f70480e547b2
  • 566ef5484da0a93c87dd0cb0a950a7cff4ab013175289cd5fccf9dd7ea430739
  • ccda8247360a85b6c076527e438a995757b6cdf5530f38e125915d31291c00d5
  • 87b4020bcd3fad1f5711e6801ca269ef5852256eeaf350f4dde2dc46c576262d
  • 988776358d0e45a4907dc1f4906a916f1b3595a31fa44d8e04e563a32557eb42
  • 3805f299d33ef43d17a5a1040149f0e5e2d5db57ec6f03c5687ac23db1f77a30
  • abba655df92e99a15ddcde1d196ff4393a13dbff293e45f5375a2f61c84a2c7b
  • a546ef13e8a71a8b5f0803075382eb0311d0d8dbae3f08bac0b2f4250af8add0

Btc

7 total
  • bc1qr0txunr259we37wer7w6et33qyq0n6hv83pw24
  • bc1q6dqe4esmqejmxhpj95qadv0j4clsqcxxp4cd94
  • bc1qandfxc4knaf943njca77edl9mmegzs83tv8lpx
  • bc1qr0pqfghr9cksfc5arr2rak3lt2y50v03pc76nh
  • bc1qpwwtck0zhzrj56fxeayz6wz5546nlp607qzpvh
  • bc1qghj85gz0dkr9jeucana3z4xu50ujtllj50rvj0
  • bc1qcnw5v94y40ast06eatgalnjpluu2p067qewh46

Recent claims

Reported operators

Threat actors

8 named in public reporting
Akira

A potential undisclosed zero-day vulnerability in SonicWall Gen 7 firewall appliances is believed to be exploited by threat actors, leading to the deployment of Akira ransomware.

UNC5221

In this special Cyber Intelligence Briefing, our cyber experts at S-RM, Ineta Simkunaite and Callum Wilson, unravel a recent encounter with the Akira ransomware group. Their review unveils a novel privilege escalation technique used by attackers.

WIZARD SPIDER

The crown jewel of their operations is the use of the ransomware that gives them their name: Akira ... It retains various capabilities such as controlling disk drives, managing running processes, multi-threaded operation, and, of course, encrypting files and writing ransom notes on the victim’s devices.

Scattered Spider

These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)

Storm-1175

In July 2024, Microsoft also linked the Storm-1175 threat group, along with three other cybercrime gangs, to Black Basta and Akira ransomware attacks that exploited a VMware ESXi authentication-bypass flaw.

Storm-0506

"...the use of this technique has led to Akira and Black Basta ransomware deployments."

INDRIK SPIDER

"...the use of this technique has led to Akira and Black Basta ransomware deployments."

Conti

In 2024, the top 3 ransomware threats to Canada were: Akira... emerged in April 2023... operates 2 ransomware variants... exfiltrates victim data before encrypting... double extortion.

Exploited software

Vulnerabilities linked to Akira

25 CVEs
CVE-2024-40766 Improper Access Control in SonicWall SonicOS Management Access and SSLVPN CVE-2023-20269 Unauthorized Access and Brute-Force Exposure in Cisco ASA and FTD Remote Access VPN CVE-2019-6693 Hard-coded Cryptographic Key in FortiOS Configuration Backups CVE-2022-40684 Authentication Bypass in Fortinet FortiOS, FortiProxy, and FortiSwitchManager Administrative Interface CVE-2021-21972 Unauthenticated RCE in VMware vCenter Server vROPS Plugin CVE-2023-48788 Fortinet FortiClient EMS DB2 Administration Server SQL Injection RCE CVE-2020-3259 Information Disclosure in Cisco ASA and Cisco FTD Web Services Interface CVE-2023-27532 Unauthenticated Credential Extraction in Veeam Backup & Replication CVE-2024-40711 Unauthenticated RCE in Veeam Backup & Replication CVE-2024-37085 Authentication Bypass in VMware ESXi Active Directory Integration CVE-2024-12802 MFA Bypass in SonicWall SSL-VPN Active Directory Authentication CVE-2023-20263 Open Redirect in Cisco HyperFlex HX Data Platform Web Management Interface CVE-2023-48365 DoubleQlik: Unauthenticated RCE in Qlik Sense Enterprise for Windows CVE-2025-23006 SonicWall SMA1000 AMC/CMC Pre-Authentication Deserialization RCE CVE-2024-21762 Fortinet FortiOS and FortiProxy SSL-VPN Out-of-Bounds Write RCE CVE-2023-27997 XORtigate CVE-2025-55182 React2Shell CVE-2025-23120 Remote Code Execution in Veeam Backup & Replication CVE-2025-7771 Arbitrary Physical Memory Read/Write in TechPowerUp ThrottleStop.sys CVE-2024-53704 SonicWall SonicOS SSLVPN Authentication Bypass CVE-2023-28252 Windows CLFS Driver Heap-Based Buffer Overflow Elevation of Privilege CVE-2020-3580 Cross-Site Scripting in Cisco ASA and Firepower FTD Web Services Interface CVE-2025-59287 Windows Server Update Services Insecure Deserialization RCE CVE-2021-20028 SQL Injection in SonicWall Secure Remote Access (SRA) Appliances CVE-2019-7481 SQL Injection in SonicWall SMA100

MITRE ATT&CK

Akira in ATT&CK

91 distinct techniques

Techniques

91 techniques
T1567 Exfiltration Over Web Service T1213 Data from Information Repositories T1486 Data Encrypted for Impact T1005 Data from Local System T1657 Financial Theft T1041 Exfiltration Over C2 Channel T1136 Create Account T1090 Proxy T1016 System Network Configuration Discovery T1098 Account Manipulation T1482 Domain Trust Discovery T1047 Windows Management Instrumentation T1555 Credentials from Password Stores T1562 Impair Defenses T1021 Remote Services T1560 Archive Collected Data T1219 Remote Access Tools T1046 Network Service Discovery T1078 Valid Accounts T1003 OS Credential Dumping T1070.004 File Deletion T1059.001 PowerShell T1190 Exploit Public-Facing Application T1105 Ingress Tool Transfer T1048 Exfiltration Over Alternative Protocol T1111 Multi-Factor Authentication Interception T1033 System Owner/User Discovery T1110.003 Password Spraying T1567.002 Exfiltration to Cloud Storage T1133 External Remote Services T1112 Modify Registry T1087 Account Discovery T1021.001 Remote Desktop Protocol T1562.009 Safe Mode Boot T1537 Transfer Data to Cloud Account T1489 Service Stop T1490 Inhibit System Recovery T1106 Native API T1135 Network Share Discovery T1485 Data Destruction T1562.001 Disable or Modify Tools T1529 System Shutdown/Reboot T1018 Remote System Discovery T1059 Command and Scripting Interpreter T1547.001 Registry Run Keys / Startup Folder T1074 Data Staged T1098.004 SSH Authorized Keys T1110 Brute Force T1210 Exploitation of Remote Services T1003.003 NTDS T1562.004 Disable or Modify System Firewall T1020 Automated Exfiltration T1082 System Information Discovery T1484.001 Group Policy Modification T1569.002 Service Execution T1036 Masquerading T1083 File and Directory Discovery T1057 Process Discovery T1027 Obfuscated Files or Information T1570 Lateral Tool Transfer T1608.006 SEO Poisoning T1583 Acquire Infrastructure T1021.002 SMB/Windows Admin Shares T1584.006 Web Services T1003.001 LSASS Memory T1053.005 Scheduled Task T1572 Protocol Tunneling T1569 System Services T1560.001 Archive via Utility T1587.001 Malware T1553.002 Code Signing T1059.003 Windows Command Shell T1566 Phishing T1543.003 Windows Service T1552 Unsecured Credentials T1565 Data Manipulation T1068 Exploitation for Privilege Escalation T1078.002 Valid Accounts: Domain Accounts T1059.002 System Services: Service Execution T1136.001 Create Account: Local Account T1136.002 Create Account: Domain Account TA0004 Privilege Escalation T1027.001 Obfuscated Files or Information: Binary Padding T1036.005 Masquerading: Match Legitimate Resource Name or Location T1558 Steal or Forge Kerberos Tickets TA0007 Discovery T1213.002 Data from Information Repositories: Sharepoint T1048.003 Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol T1229 Remote Access Software T1531 Account Access Removal T1685 Disable or Modify Tools

Reporting

Research mentioning Akira

Aug 26
Zdnet Zero Day

July was the worst month for ransomware victim claims in 2026 - or was it? | ZDNET

Security reporting has documented LameHug as the first publicly known malware to integrate a large language model, marking an escalation in the use of generative AI within malicious tooling. The development indicates that AI can be incorporated into malware operations rather than being used solely to create phishing content or assist attackers outside the payload. Separately, ransomware victim listings reached 894 organizations in July 2026, according to NCC Group data cited by ZDNET, with industrial organizations comprising nearly one-third of listed victims. The reporting also identified the first documented fully agentic AI ransomware attack chain, attributed to JadePuffer, amid a surge led by groups including The Gentlemen and Qilin; however, organizations should treat leak-site claims cautiously because some actors, including the new CRPxO RaaS operation, may inflate or fabricate victim listings.

Aug 20
Hookphish

Ransomware Group qilin Hits: Trends And Concepts

Researchers reported that the Agenda ransomware operation, also tracked as Qilin, is conducting highly customized enterprise attacks across Asia and Africa and has now been linked to a victim in South Africa. A recent victim listing identified Trends And Concepts in South Africa, associated with the domain www.trendsandconceptsinteriors.com, as impacted by the Qilin group. Trend researchers said Agenda operators build victim-specific Go-based payloads that can include leaked account credentials, unique company identifiers, customized RSA keys, and ransom demands ranging from $50,000 to $800,000, with observed targeting of healthcare and education organizations in Indonesia, Saudi Arabia, South Africa, and Thailand. The intrusion methods described across the reports show a flexible and increasingly sophisticated playbook. In one case, attackers accessed a public-facing Citrix server using a valid account, moved laterally with RDP and leaked Active Directory credentials, scanned networks with Nmap and Nping, and deployed ransomware through Group Policy in under two days. A separate Trend investigation found Agenda actors using fake Google CAPTCHA pages to deliver credential stealers, then abusing legitimate remote-management tools including ATERA, AnyDesk, ScreenConnect, and Splashtop, while deploying COROXY SOCKS proxies, targeting Veeam backup infrastructure, and using BYOVD techniques with vulnerable drivers such as eskle.sys; the final ransomware payload was reportedly a Linux variant executed on Windows, likely through Windows Subsystem for Linux.

Aug 19
Trendai Security

Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques | TrendAI (US)

Aug 14
Trendai Security

New Golang Ransomware Agenda Customizes Attacks | TrendAI (US)

Aug 12
Register Security

Akira ransomware scum blocked victim's security tools - and broke their own encryptor

An Akira ransomware affiliate breached a victim through a SonicWall SSL VPN account that lacked MFA after a credential-spraying attempt, then used RDP and Active Directory enumeration to map the environment, collect data, and stage exfiltration. Huntress reported the attacker created AdUsers.txt and AdComp.txt with PowerShell-based AD dumps, used WinRAR to package files, s5cmd to move data to S3, and installed AnyDesk for persistent remote access and payload delivery before launching the Akira encryptor. The intrusion’s notable defense-evasion step was forcing a compromised Windows host to reboot into Safe Mode with Networking, a technique tracked by MITRE ATT&CK as T1688, to disable endpoint protections while preserving connectivity. In Safe Mode, the Huntress agent and Microsoft Defender real-time protection were suppressed, but the Akira encryptor appears to have hit virtual-memory errors and failed to complete encryption; Defender later detected akira.exe yet could not quarantine it until the system returned to normal mode. Researchers warned the failure was accidental rather than protective, and urged organizations to enforce MFA on VPN access and monitor for failed VPN login bursts, Safe Mode boot changes, and unexpected security-service stoppages.

Aug 12
Huntress

Akira Hits Safe Mode: Ransomware Rebooting Around EDR | Huntress

Jul 22
Belgium Ccb News

Threat Intelligence Report: Qilin (Agenda) Ransomware | CCB Belgium

Qilin ransomware has emerged as one of the most active cybercrime threats, with NCC Group identifying it as the most prolific ransomware group for the fifth consecutive quarter as global ransomware incidents climbed to 2,229 in Q2 2026. The group, also tracked as Agenda or Qilin Locker, operates a double-extortion RaaS model and has concentrated on high-GDP Western countries while reportedly avoiding CIS member states. Manufacturing and other industrial sectors have been hit hardest, alongside business services, technology, healthcare, and finance, with North America remaining the most affected region and Belgium reporting at least 15 alleged Qilin compromises that disrupted operations and exposed sensitive corporate data.

Jul 22
Itsecurityguru

Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns - IT Security Guru

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.