Credential Theft
- DonPAPI
- LaZagne
- Mimikatz
Akira is a ransomware operation active since 2023 that has become one of the more prominent extortion threats affecting enterprise environments.
Profile source: Mallory opens in a new tabAkira
Akira is a ransomware operation active since 2023 that has become one of the more prominent extortion threats affecting enterprise environments. It is associated with double-extortion activity, combining file encryption with data theft and threats to publish stolen information. Reporting through 2025 and 2026 places Akira among the more active ransomware groups globally, with repeated victimization across manufacturing, construction, healthcare, energy, education, financial services, retail, and other mid-market and enterprise sectors.
Akira has been repeatedly linked to intrusions that begin through compromised remote access infrastructure and exposed edge devices, especially VPN and firewall products. High-confidence reporting ties the group to exploitation of authentication-bypass and other vulnerabilities affecting SonicWall devices, and broader reporting also places Akira among ransomware actors abusing weaknesses in products from vendors such as Fortinet, Citrix, and Check Point to gain an initial foothold. In addition to vulnerability exploitation, Akira has been discussed in the broader ransomware ecosystem alongside phishing, identity abuse, stolen credentials, and remote access compromise as common entry paths, but direct malware-specific delivery evidence is strongest for edge-device exploitation.
Operationally, Akira intrusions are associated with lateral movement, post-compromise network expansion, and exfiltration prior to extortion. Public reporting also links Akira tradecraft to the use of tunneling utilities in some campaigns, although not every such observation is attributed with high confidence. Akira has been observed targeting Windows environments and VMware ESXi, and U.S. government reporting in late 2025 stated that the operation had expanded to encrypt Nutanix virtualization platforms as well. The group has accumulated substantial ransom proceeds since its emergence and remains a significant threat to organizations that expose remote access services or fail to harden perimeter infrastructure.
083740c55d0a459674457b8551ed9c6a1a7df536c3bb676a6f90af5b3bea53024d43e35962c8c7fdca5f64da8f561f5af17b6cdcbac9462f01da65bd4f8636db27182f9017d8e4212fbc32e954e19d37ab359be0ab33876eb32325706e43f0c11d895cf4391b817e54fb9ec9d8e65f7e03b9887dee2c3c825b6a6c0df1d104ad4d79fb750955ec8702cb79cfdb36e66bc387b2eb96bb137cdd54220d920edce978d75669390e4177597faf9271ce3ad3a16a3652e145913dbfa9a5951972fcb02c7aeac07ce7f03b74952e0e243bd52f2bfa60fadc92dd71a6a1fee2d14cdd7788da2b1cee373d5f11949c1ade22af0badf16591a871978a9e02f70480e547b2566ef5484da0a93c87dd0cb0a950a7cff4ab013175289cd5fccf9dd7ea430739ccda8247360a85b6c076527e438a995757b6cdf5530f38e125915d31291c00d587b4020bcd3fad1f5711e6801ca269ef5852256eeaf350f4dde2dc46c576262d988776358d0e45a4907dc1f4906a916f1b3595a31fa44d8e04e563a32557eb423805f299d33ef43d17a5a1040149f0e5e2d5db57ec6f03c5687ac23db1f77a30abba655df92e99a15ddcde1d196ff4393a13dbff293e45f5375a2f61c84a2c7ba546ef13e8a71a8b5f0803075382eb0311d0d8dbae3f08bac0b2f4250af8add0bc1qr0txunr259we37wer7w6et33qyq0n6hv83pw24bc1q6dqe4esmqejmxhpj95qadv0j4clsqcxxp4cd94bc1qandfxc4knaf943njca77edl9mmegzs83tv8lpxbc1qr0pqfghr9cksfc5arr2rak3lt2y50v03pc76nhbc1qpwwtck0zhzrj56fxeayz6wz5546nlp607qzpvhbc1qghj85gz0dkr9jeucana3z4xu50ujtllj50rvj0bc1qcnw5v94y40ast06eatgalnjpluu2p067qewh46Reported operators
Figure 3 below represents the total number of victims claimed by The Gentlemen in 2025 compared to both Qilin and Akira, tracked by Unit 42 as Howling Scorpius.
The crown jewel of their operations is the use of the ransomware that gives them their name: Akira ... It retains various capabilities such as controlling disk drives, managing running processes, multi-threaded operation, and, of course, encrypting files and writing ransom notes on the victim’s devices.
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
In July 2024, Microsoft also linked the Storm-1175 threat group, along with three other cybercrime gangs, to Black Basta and Akira ransomware attacks that exploited a VMware ESXi authentication-bypass flaw.
"...the use of this technique has led to Akira and Black Basta ransomware deployments."
"...the use of this technique has led to Akira and Black Basta ransomware deployments."
In 2024, the top 3 ransomware threats to Canada were: Akira... emerged in April 2023... operates 2 ransomware variants... exfiltrates victim data before encrypting... double extortion.
Exploited software
MITRE ATT&CK
Reporting
Qilin ransomware has emerged as one of the most active cybercrime threats, with NCC Group identifying it as the most prolific ransomware group for the fifth consecutive quarter as global ransomware incidents climbed to 2,229 in Q2 2026. The group, also tracked as Agenda or Qilin Locker, operates a double-extortion RaaS model and has concentrated on high-GDP Western countries while reportedly avoiding CIS member states. Manufacturing and other industrial sectors have been hit hardest, alongside business services, technology, healthcare, and finance, with North America remaining the most affected region and Belgium reporting at least 15 alleged Qilin compromises that disrupted operations and exposed sensitive corporate data.
Ransomware and cyber-extortion activity rose again in Q2 2026, with industry reporting showing more than 2,250 publicly named victims across roughly 90 active groups and nearly 100 countries. GuidePoint Security’s GRIT report counted 2,279 victims, up 7% from the prior quarter and 43% year over year, while ReliaQuest recorded 2,252 victims and found the United States accounted for about 49% of observed activity. Qilin remained a leading force in one dataset for a fifth straight quarter, while The Gentlemen surged into the top tier and was ranked the most active group by ReliaQuest; DragonForce also remained prominent despite reported declines in some rankings. Professional, scientific, and technical services stayed the most targeted sector, and researchers noted a broader shift toward data-only extortion and continued pressure on organizations through public leak-site exposure. Researchers also highlighted technical changes in attacker tradecraft rather than a wholesale change in ransomware operations. The quarter saw increased use of AI and LLMs by threat actors, including analysis of exfiltrated databases and more tailored extortion messaging, alongside continued exploitation of high-impact vulnerabilities such as CVE-2026-50751, CVE-2026-48027, CVE-2026-46817, and CVE-2026-35273. ReliaQuest identified Deadlock as a notable re-emerging threat after 11 months of silence, using blockchain-hosted command-and-control through a Polygon smart contract and a BYOVD technique to terminate EDR tools via CVE-2024-51324. The reports say supply-chain compromise, remote access abuse, identity attacks, lateral movement, and defense evasion remain central to ransomware operations even as payment rates decline.
SonicWall has patched two vulnerabilities that are being actively exploited against SMA 1000 Series appliances, affecting models including 6210, 7210, and 8200v. The flaws, tracked as CVE-2026-15409 and CVE-2026-15410, impact multiple 12.4.3 and 12.5.0 platform-hotfix releases. SonicWall described CVE-2026-15409 as a critical unauthenticated SSRF issue in the Appliance Work Place interface and CVE-2026-15410 as a high-severity code injection flaw in the Appliance Management Console that can allow an authenticated administrator to execute arbitrary operating system commands. SonicWall said the vulnerabilities have been exploited together in the wild and released hotfixes to address them. Government and vendor advisories urged organizations to update immediately and investigate appliances for signs of compromise, warning that patching alone may not be sufficient if an appliance has already been breached. SonicWall recommended reviewing logs, re-imaging or re-deploying affected systems where indicators are found, changing user and administrator passwords, and resetting TOTP tokens. The Canadian Centre for Cyber Security highlighted the advisory, and CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog the same day, underscoring the urgency for defenders to remediate exposed SMA1000 deployments.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.