Credential Theft
- DonPAPI
- LaZagne
- Mimikatz
Akira is a ransomware operation active since March 2023 that conducts double-extortion attacks against corporate networks.
Profile source: Mallory opens in a new tabAkira
Akira is a ransomware operation active since March 2023 that conducts double-extortion attacks against corporate networks. Affiliates have gained access through compromised VPN credentials, exposed remote-access services, exploitation of known vulnerabilities in perimeter appliances, and credential attacks. Observed intrusions include discovery and Active Directory enumeration, creation of local and domain accounts, use of legitimate remote-management tools, lateral movement over RDP and SMB administrative shares, and theft of corporate data before encryption. Akira operators have targeted backup infrastructure and recovery mechanisms, including Veeam environments and Volume Shadow Copies, and have attempted to disable endpoint security controls; one observed affiliate used Safe Mode with Networking to impair EDR protections. The ransomware encrypts a broad range of business, database, virtual-machine, disk-image, and backup-related data while avoiding selected operating-system and executable files. It can use the Windows Restart Manager API to stop processes and services that obstruct encryption. Akira uses a leak site and Tor-based negotiation portal to pressure victims with threatened publication or sale of stolen data. Victims span numerous sectors, including construction, manufacturing, education, finance, real estate, consulting, technology, healthcare, and professional services, with substantial activity reported against organizations in the United States and North America.
083740c55d0a459674457b8551ed9c6a1a7df536c3bb676a6f90af5b3bea53024d43e35962c8c7fdca5f64da8f561f5af17b6cdcbac9462f01da65bd4f8636db27182f9017d8e4212fbc32e954e19d37ab359be0ab33876eb32325706e43f0c11d895cf4391b817e54fb9ec9d8e65f7e03b9887dee2c3c825b6a6c0df1d104ad4d79fb750955ec8702cb79cfdb36e66bc387b2eb96bb137cdd54220d920edce978d75669390e4177597faf9271ce3ad3a16a3652e145913dbfa9a5951972fcb02c7aeac07ce7f03b74952e0e243bd52f2bfa60fadc92dd71a6a1fee2d14cdd7788da2b1cee373d5f11949c1ade22af0badf16591a871978a9e02f70480e547b2566ef5484da0a93c87dd0cb0a950a7cff4ab013175289cd5fccf9dd7ea430739ccda8247360a85b6c076527e438a995757b6cdf5530f38e125915d31291c00d587b4020bcd3fad1f5711e6801ca269ef5852256eeaf350f4dde2dc46c576262d988776358d0e45a4907dc1f4906a916f1b3595a31fa44d8e04e563a32557eb423805f299d33ef43d17a5a1040149f0e5e2d5db57ec6f03c5687ac23db1f77a30abba655df92e99a15ddcde1d196ff4393a13dbff293e45f5375a2f61c84a2c7ba546ef13e8a71a8b5f0803075382eb0311d0d8dbae3f08bac0b2f4250af8add0bc1qr0txunr259we37wer7w6et33qyq0n6hv83pw24bc1q6dqe4esmqejmxhpj95qadv0j4clsqcxxp4cd94bc1qandfxc4knaf943njca77edl9mmegzs83tv8lpxbc1qr0pqfghr9cksfc5arr2rak3lt2y50v03pc76nhbc1qpwwtck0zhzrj56fxeayz6wz5546nlp607qzpvhbc1qghj85gz0dkr9jeucana3z4xu50ujtllj50rvj0bc1qcnw5v94y40ast06eatgalnjpluu2p067qewh46Reported operators
A potential undisclosed zero-day vulnerability in SonicWall Gen 7 firewall appliances is believed to be exploited by threat actors, leading to the deployment of Akira ransomware.
In this special Cyber Intelligence Briefing, our cyber experts at S-RM, Ineta Simkunaite and Callum Wilson, unravel a recent encounter with the Akira ransomware group. Their review unveils a novel privilege escalation technique used by attackers.
The crown jewel of their operations is the use of the ransomware that gives them their name: Akira ... It retains various capabilities such as controlling disk drives, managing running processes, multi-threaded operation, and, of course, encrypting files and writing ransom notes on the victim’s devices.
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
In July 2024, Microsoft also linked the Storm-1175 threat group, along with three other cybercrime gangs, to Black Basta and Akira ransomware attacks that exploited a VMware ESXi authentication-bypass flaw.
"...the use of this technique has led to Akira and Black Basta ransomware deployments."
"...the use of this technique has led to Akira and Black Basta ransomware deployments."
In 2024, the top 3 ransomware threats to Canada were: Akira... emerged in April 2023... operates 2 ransomware variants... exfiltrates victim data before encrypting... double extortion.
Exploited software
MITRE ATT&CK
Reporting
Security reporting has documented LameHug as the first publicly known malware to integrate a large language model, marking an escalation in the use of generative AI within malicious tooling. The development indicates that AI can be incorporated into malware operations rather than being used solely to create phishing content or assist attackers outside the payload. Separately, ransomware victim listings reached 894 organizations in July 2026, according to NCC Group data cited by ZDNET, with industrial organizations comprising nearly one-third of listed victims. The reporting also identified the first documented fully agentic AI ransomware attack chain, attributed to JadePuffer, amid a surge led by groups including The Gentlemen and Qilin; however, organizations should treat leak-site claims cautiously because some actors, including the new CRPxO RaaS operation, may inflate or fabricate victim listings.
Researchers reported that the Agenda ransomware operation, also tracked as Qilin, is conducting highly customized enterprise attacks across Asia and Africa and has now been linked to a victim in South Africa. A recent victim listing identified Trends And Concepts in South Africa, associated with the domain www.trendsandconceptsinteriors.com, as impacted by the Qilin group. Trend researchers said Agenda operators build victim-specific Go-based payloads that can include leaked account credentials, unique company identifiers, customized RSA keys, and ransom demands ranging from $50,000 to $800,000, with observed targeting of healthcare and education organizations in Indonesia, Saudi Arabia, South Africa, and Thailand. The intrusion methods described across the reports show a flexible and increasingly sophisticated playbook. In one case, attackers accessed a public-facing Citrix server using a valid account, moved laterally with RDP and leaked Active Directory credentials, scanned networks with Nmap and Nping, and deployed ransomware through Group Policy in under two days. A separate Trend investigation found Agenda actors using fake Google CAPTCHA pages to deliver credential stealers, then abusing legitimate remote-management tools including ATERA, AnyDesk, ScreenConnect, and Splashtop, while deploying COROXY SOCKS proxies, targeting Veeam backup infrastructure, and using BYOVD techniques with vulnerable drivers such as eskle.sys; the final ransomware payload was reportedly a Linux variant executed on Windows, likely through Windows Subsystem for Linux.
An Akira ransomware affiliate breached a victim through a SonicWall SSL VPN account that lacked MFA after a credential-spraying attempt, then used RDP and Active Directory enumeration to map the environment, collect data, and stage exfiltration. Huntress reported the attacker created AdUsers.txt and AdComp.txt with PowerShell-based AD dumps, used WinRAR to package files, s5cmd to move data to S3, and installed AnyDesk for persistent remote access and payload delivery before launching the Akira encryptor. The intrusion’s notable defense-evasion step was forcing a compromised Windows host to reboot into Safe Mode with Networking, a technique tracked by MITRE ATT&CK as T1688, to disable endpoint protections while preserving connectivity. In Safe Mode, the Huntress agent and Microsoft Defender real-time protection were suppressed, but the Akira encryptor appears to have hit virtual-memory errors and failed to complete encryption; Defender later detected akira.exe yet could not quarantine it until the system returned to normal mode. Researchers warned the failure was accidental rather than protective, and urged organizations to enforce MFA on VPN access and monitor for failed VPN login bursts, Safe Mode boot changes, and unexpected security-service stoppages.
Qilin ransomware has emerged as one of the most active cybercrime threats, with NCC Group identifying it as the most prolific ransomware group for the fifth consecutive quarter as global ransomware incidents climbed to 2,229 in Q2 2026. The group, also tracked as Agenda or Qilin Locker, operates a double-extortion RaaS model and has concentrated on high-GDP Western countries while reportedly avoiding CIS member states. Manufacturing and other industrial sectors have been hit hardest, alongside business services, technology, healthcare, and finance, with North America remaining the most affected region and Belgium reporting at least 15 alleged Qilin compromises that disrupted operations and exposed sensitive corporate data.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.