Skip to content

Akira

Akira is a ransomware operation active since 2023 that has become one of the more prominent extortion threats affecting enterprise environments.

Profile source: Mallory opens in a new tab

Akira

Family profile

Akira is a ransomware operation active since 2023 that has become one of the more prominent extortion threats affecting enterprise environments. It is associated with double-extortion activity, combining file encryption with data theft and threats to publish stolen information. Reporting through 2025 and 2026 places Akira among the more active ransomware groups globally, with repeated victimization across manufacturing, construction, healthcare, energy, education, financial services, retail, and other mid-market and enterprise sectors.

Akira has been repeatedly linked to intrusions that begin through compromised remote access infrastructure and exposed edge devices, especially VPN and firewall products. High-confidence reporting ties the group to exploitation of authentication-bypass and other vulnerabilities affecting SonicWall devices, and broader reporting also places Akira among ransomware actors abusing weaknesses in products from vendors such as Fortinet, Citrix, and Check Point to gain an initial foothold. In addition to vulnerability exploitation, Akira has been discussed in the broader ransomware ecosystem alongside phishing, identity abuse, stolen credentials, and remote access compromise as common entry paths, but direct malware-specific delivery evidence is strongest for edge-device exploitation.

Operationally, Akira intrusions are associated with lateral movement, post-compromise network expansion, and exfiltration prior to extortion. Public reporting also links Akira tradecraft to the use of tunneling utilities in some campaigns, although not every such observation is attributed with high confidence. Akira has been observed targeting Windows environments and VMware ESXi, and U.S. government reporting in late 2025 stated that the operation had expanded to encrypt Nutanix virtualization platforms as well. The group has accumulated substantial ransom proceeds since its emergence and remains a significant threat to organizations that expose remote access services or fail to harden perimeter infrastructure.

Capabilities

  • Exfiltration
  • Initial Access
  • Lateral Movement
  • Post Exploitation

Operational record

365
Indicators
1
YARA rules
3
Ransom notes
76
Negotiations
2
Leak sites
2 available

Credential Theft

  • DonPAPI
  • LaZagne
  • Mimikatz

Defense Evasion

  • PowerTool
  • ThrottleStop driver
  • Zemana Anti-Rootkit driver
  • churchill_driver.sys / fidget.sys
  • consent.exe (msimg32.dll / wmsgapi.dll)
  • icardagt.exe (version.dll DLL sideload)
  • mfpmp.exe (rtworkq.dll DLL sideload)

Discovery Enum

  • Advanced IP Scanner
  • Advanced Port Scanner
  • Bloodhound
  • Masscan
  • ReconFTW
  • ShareFinder
  • SharpHound
  • SharpShares
  • SoftPerfect NetScan
  • ldapdomaindump

Exfiltration

  • FileZilla
  • MEGA
  • RClone
  • Temp[.]sh
  • WinRAR
  • WinSCP

LOLBAS

  • net
  • netsh
  • nltest
  • vssadmin

Networking

  • Cloudflared
  • Ngrok
  • OpenSSH

Offsec

  • CrackMapExec
  • Impacket
  • NetExec

RMM Tools

  • AnyDesk
  • MeshAgent
  • MobaXterm
  • Radmin
  • RustDesk
  • TeamViewer

Published indicators

Md5

320 total
  • 083740c55d0a459674457b8551ed9c6a
  • 1a7df536c3bb676a6f90af5b3bea5302
  • 4d43e35962c8c7fdca5f64da8f561f5a
  • f17b6cdcbac9462f01da65bd4f8636db
  • 27182f9017d8e4212fbc32e954e19d37
  • ab359be0ab33876eb32325706e43f0c1
  • 1d895cf4391b817e54fb9ec9d8e65f7e
  • 03b9887dee2c3c825b6a6c0df1d104ad
  • 4d79fb750955ec8702cb79cfdb36e66b
  • c387b2eb96bb137cdd54220d920edce9

Sha256

37 total
  • 78d75669390e4177597faf9271ce3ad3a16a3652e145913dbfa9a5951972fcb0
  • 2c7aeac07ce7f03b74952e0e243bd52f2bfa60fadc92dd71a6a1fee2d14cdd77
  • 88da2b1cee373d5f11949c1ade22af0badf16591a871978a9e02f70480e547b2
  • 566ef5484da0a93c87dd0cb0a950a7cff4ab013175289cd5fccf9dd7ea430739
  • ccda8247360a85b6c076527e438a995757b6cdf5530f38e125915d31291c00d5
  • 87b4020bcd3fad1f5711e6801ca269ef5852256eeaf350f4dde2dc46c576262d
  • 988776358d0e45a4907dc1f4906a916f1b3595a31fa44d8e04e563a32557eb42
  • 3805f299d33ef43d17a5a1040149f0e5e2d5db57ec6f03c5687ac23db1f77a30
  • abba655df92e99a15ddcde1d196ff4393a13dbff293e45f5375a2f61c84a2c7b
  • a546ef13e8a71a8b5f0803075382eb0311d0d8dbae3f08bac0b2f4250af8add0

Btc

7 total
  • bc1qr0txunr259we37wer7w6et33qyq0n6hv83pw24
  • bc1q6dqe4esmqejmxhpj95qadv0j4clsqcxxp4cd94
  • bc1qandfxc4knaf943njca77edl9mmegzs83tv8lpx
  • bc1qr0pqfghr9cksfc5arr2rak3lt2y50v03pc76nh
  • bc1qpwwtck0zhzrj56fxeayz6wz5546nlp607qzpvh
  • bc1qghj85gz0dkr9jeucana3z4xu50ujtllj50rvj0
  • bc1qcnw5v94y40ast06eatgalnjpluu2p067qewh46

Recent claims

Reported operators

Threat actors

7 named in public reporting
Akira

Figure 3 below represents the total number of victims claimed by The Gentlemen in 2025 compared to both Qilin and Akira, tracked by Unit 42 as Howling Scorpius.

WIZARD SPIDER

The crown jewel of their operations is the use of the ransomware that gives them their name: Akira ... It retains various capabilities such as controlling disk drives, managing running processes, multi-threaded operation, and, of course, encrypting files and writing ransom notes on the victim’s devices.

Scattered Spider

These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)

Storm-1175

In July 2024, Microsoft also linked the Storm-1175 threat group, along with three other cybercrime gangs, to Black Basta and Akira ransomware attacks that exploited a VMware ESXi authentication-bypass flaw.

Storm-0506

"...the use of this technique has led to Akira and Black Basta ransomware deployments."

INDRIK SPIDER

"...the use of this technique has led to Akira and Black Basta ransomware deployments."

Conti

In 2024, the top 3 ransomware threats to Canada were: Akira... emerged in April 2023... operates 2 ransomware variants... exfiltrates victim data before encrypting... double extortion.

Exploited software

Vulnerabilities linked to Akira

25 CVEs
CVE-2024-40766 Improper Access Control in SonicWall SonicOS Management and SSLVPN Access CVE-2023-20269 Unauthorized Access in Cisco ASA and FTD Remote Access VPN CVE-2023-48788 SQL Injection Leading to RCE in Fortinet FortiClient EMS CVE-2020-3259 Cisco ASA/FTD Web Services Interface Memory Disclosure CVE-2023-27532 Missing Authentication in Veeam Backup & Replication Cloud Connect Credential Retrieval CVE-2024-40711 Unauthenticated RCE in Veeam Backup & Replication CVE-2024-37085 Authentication Bypass in VMware ESXi Active Directory Integration CVE-2024-12802 MFA Bypass in SonicWall SSL-VPN Active Directory Authentication CVE-2023-20263 Open Redirect in Cisco HyperFlex HX Data Platform Web Management Interface CVE-2023-48365 DoubleQlik / HTTP Tunneling RCE in Qlik Sense Enterprise for Windows CVE-2025-23006 SonicWall SMA1000 AMC/CMC Pre-Authentication Deserialization RCE CVE-2024-21762 Fortinet FortiOS/FortiProxy SSL-VPN Out-of-Bounds Write RCE CVE-2023-27997 XORtigate: Heap-Based Buffer Overflow RCE in FortiOS and FortiProxy SSL-VPN CVE-2025-55182 React2Shell CVE-2025-23120 Remote Code Execution in Veeam Backup & Replication CVE-2025-7771 Arbitrary Physical Memory Read/Write in TechPowerUp ThrottleStop.sys CVE-2024-53704 SonicWall SonicOS SSLVPN Authentication Bypass CVE-2023-28252 Windows Common Log File System Driver Elevation of Privilege CVE-2020-3580 XSS in Cisco ASA/FTD Web Services Interface (AnyConnect/WebVPN) CVE-2025-59287 Unauthenticated RCE in Windows Server Update Services AuthorizationCookie Deserialization CVE-2021-20028 SQL Injection in SonicWall Secure Remote Access (SRA) CVE-2019-7481 SQL Injection in SonicWall SMA100 CVE-2022-40684 Fortinet FortiOS - CRITICAL - CVSS 9.8 CVE-2019-6693 Fortinet FortiOS - MEDIUM - CVSS 6.5 CVE-2021-21972 VMware vSphere Client - CRITICAL - CVSS 9.8

MITRE ATT&CK

Akira in ATT&CK

95 distinct techniques

Techniques

95 techniques
T1486 Data Encrypted for Impact T1657 Financial Theft T1567 Exfiltration Over Web Service T1136 Create Account T1098.004 SSH Authorized Keys T1562 Impair Defenses T1190 Exploit Public-Facing Application T1078 Valid Accounts T1110 Brute Force T1133 External Remote Services T1210 Exploitation of Remote Services T1562.001 Disable or Modify Tools T1003.003 NTDS T1562.004 Disable or Modify System Firewall T1041 Exfiltration Over C2 Channel T1074 Data Staged T1020 Automated Exfiltration T1082 System Information Discovery T1484.001 Group Policy Modification T1490 Inhibit System Recovery T1569.002 Service Execution T1036 Masquerading T1047 Windows Management Instrumentation T1059.001 PowerShell T1083 File and Directory Discovery T1070.004 File Deletion T1057 Process Discovery T1027 Obfuscated Files or Information T1021 Remote Services T1570 Lateral Tool Transfer T1608.006 SEO Poisoning T1583 Acquire Infrastructure T1021.002 SMB/Windows Admin Shares T1584.006 Web Services T1529 System Shutdown/Reboot T1106 Native API T1219 Remote Access Tools T1021.001 Remote Desktop Protocol T1003.001 LSASS Memory T1053.005 Scheduled Task T1090 Proxy T1098 Account Manipulation T1018 Remote System Discovery T1572 Protocol Tunneling T1105 Ingress Tool Transfer T1087 Account Discovery T1569 System Services T1560.001 Archive via Utility T1046 Network Service Discovery T1587.001 Malware T1553.002 Code Signing T1059.003 Windows Command Shell T1566 Phishing T1537 Transfer Data to Cloud Account T1048 Exfiltration Over Alternative Protocol T1482 Domain Trust Discovery T1543.003 Windows Service T1560 Archive Collected Data T1016 System Network Configuration Discovery T1552 Unsecured Credentials T1489 Service Stop T1565 Data Manipulation T1068 Exploitation for Privilege Escalation T1485 Data Destruction T1003 OS Credential Dumping T1071 Application Layer Protocol T1213 Data from Information Repositories T1203 Exploitation for Client Execution T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol T1070.001 Clear Windows Event Logs T1135 Network Share Discovery T1134 Access Token Manipulation T1564.002 Hidden Users T1621 Multi-Factor Authentication Request Generation T1199 Trusted Relationship T1136.001 Local Account T1021.006 Windows Remote Management T1021.004 SSH T1555.003 Credentials from Web Browsers T1112 Modify Registry T1111 Multi-Factor Authentication Interception T1078.002 Valid Accounts: Domain Accounts T1059 Command and Scripting Interpreter T1059.002 System Services: Service Execution T1136.002 Create Account: Domain Account TA0004 Privilege Escalation T1027.001 Obfuscated Files or Information: Binary Padding T1036.005 Masquerading: Match Legitimate Resource Name or Location T1558 Steal or Forge Kerberos Tickets TA0007 Discovery T1213.002 Data from Information Repositories: Sharepoint T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage T1229 Remote Access Software T1531 Account Access Removal T1685 Disable or Modify Tools

Reporting

Research mentioning Akira

Jul 22
Belgium Ccb News

Threat Intelligence Report: Qilin (Agenda) Ransomware | CCB Belgium

Qilin ransomware has emerged as one of the most active cybercrime threats, with NCC Group identifying it as the most prolific ransomware group for the fifth consecutive quarter as global ransomware incidents climbed to 2,229 in Q2 2026. The group, also tracked as Agenda or Qilin Locker, operates a double-extortion RaaS model and has concentrated on high-GDP Western countries while reportedly avoiding CIS member states. Manufacturing and other industrial sectors have been hit hardest, alongside business services, technology, healthcare, and finance, with North America remaining the most affected region and Belgium reporting at least 15 alleged Qilin compromises that disrupted operations and exposed sensitive corporate data.

Jul 22
Itsecurityguru

Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns - IT Security Guru

Jul 21
Cyber Security News

Qilin Ransomware Claims 1,358 Victims as Global Attacks Reach New Record

Ransomware and cyber-extortion activity rose again in Q2 2026, with industry reporting showing more than 2,250 publicly named victims across roughly 90 active groups and nearly 100 countries. GuidePoint Security’s GRIT report counted 2,279 victims, up 7% from the prior quarter and 43% year over year, while ReliaQuest recorded 2,252 victims and found the United States accounted for about 49% of observed activity. Qilin remained a leading force in one dataset for a fifth straight quarter, while The Gentlemen surged into the top tier and was ranked the most active group by ReliaQuest; DragonForce also remained prominent despite reported declines in some rankings. Professional, scientific, and technical services stayed the most targeted sector, and researchers noted a broader shift toward data-only extortion and continued pressure on organizations through public leak-site exposure. Researchers also highlighted technical changes in attacker tradecraft rather than a wholesale change in ransomware operations. The quarter saw increased use of AI and LLMs by threat actors, including analysis of exfiltrated databases and more tailored extortion messaging, alongside continued exploitation of high-impact vulnerabilities such as CVE-2026-50751, CVE-2026-48027, CVE-2026-46817, and CVE-2026-35273. ReliaQuest identified Deadlock as a notable re-emerging threat after 11 months of silence, using blockchain-hosted command-and-control through a Polygon smart contract and a BYOVD technique to terminate EDR tools via CVE-2024-51324. The reports say supply-chain compromise, remote access abuse, identity attacks, lateral movement, and defense evasion remain central to ransomware operations even as payment rates decline.

Jul 21
Emsisoft

The State of Ransomware in Q2 2026

Jul 21
Cyber Security News

SonicWall 0-day Vulnerabilities Exploited in the Wild to Deploy Custom Malware

SonicWall has patched two vulnerabilities that are being actively exploited against SMA 1000 Series appliances, affecting models including 6210, 7210, and 8200v. The flaws, tracked as CVE-2026-15409 and CVE-2026-15410, impact multiple 12.4.3 and 12.5.0 platform-hotfix releases. SonicWall described CVE-2026-15409 as a critical unauthenticated SSRF issue in the Appliance Work Place interface and CVE-2026-15410 as a high-severity code injection flaw in the Appliance Management Console that can allow an authenticated administrator to execute arbitrary operating system commands. SonicWall said the vulnerabilities have been exploited together in the wild and released hotfixes to address them. Government and vendor advisories urged organizations to update immediately and investigate appliances for signs of compromise, warning that patching alone may not be sufficient if an appliance has already been breached. SonicWall recommended reviewing logs, re-imaging or re-deploying affected systems where indicators are found, changing user and administrator passwords, and resetting TOTP tokens. The Canadian Centre for Cyber Security highlighted the advisory, and CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog the same day, underscoring the urgency for defenders to remediate exposed SMA1000 deployments.

Jul 21
Socradar

SonicWall SMA Flaws Lead to KNUCKLEBALL Malware

Jul 21
Help Net Security

SonicWall SMA zero-days were exploited weeks before disclosure - Help Net Security

Jul 20
Security Week

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch - SecurityWeek

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.