Akira ransomware has emerged as one of 2023's most disciplined ransomware operations, and Sophos MDR Threat Intelligence now has the incident data to prove it. After responding to more than a dozen Akira engagements, Sophos published a detailed technical breakdown in December 2023 revealing a consistent attack chain anchored in Cisco VPN exploitation and aggressive credential harvesting.
VPN as the Preferred Front Door
The most frequently observed initial access vector across all Akira incidents was unauthorised logon to VPN accounts lacking multi-factor authentication — specifically targeting Cisco ASA SSL VPN and Cisco AnyConnect products. Cisco disclosed CVE-2023-20269, a zero-day in ASA and Firepower Threat Defense software, which Akira affiliates exploited to identify valid credentials and establish unauthorized remote access sessions.
Once inside, attackers were methodical. In one documented incident, RDP was invoked over 100 times between initial access and final encryption, spanning 15 machines. Lateral movement combined SMB, Impacket's wmiexec module, and VmConnect.exe to reach Hyper-V virtual machines through compromised administrator accounts.
Two Variants: Akira and Megazord
Sophos confirmed deployment of both the primary Akira encryptor and a secondary variant called Megazord, the latter appearing in a single August 2023 incident. In a separate engagement, analysts found a previously unreported backdoor executable used for C2 — a notable deviation from the group's normal preference for dual-use agents such as AnyDesk or Splashtop.
Where Sophos endpoint protections were active, Akira actors consistently attempted to disable or uninstall security software before deploying the encryptor, confirming deliberate pre-deployment reconnaissance.
Targets and Geography
Akira's 2023 victims spanned government, manufacturing, technology, education, consulting, pharmaceuticals, and telecommunications, concentrated in North America, Europe, and Australia. The group's double-extortion model — encrypting files while threatening to publish data via a Tor-hosted retro terminal interface — ensures leverage even against organisations with functional backups.
"As Akira continues to leverage a variety of credential access and defense evasion techniques, Sophos continues to closely monitor Akira ransomware activity and track their evolving tactics."
Defenders should enforce phishing-resistant MFA on all VPN products, monitor for wmiexec and PsExec lateral movement, and audit Hyper-V management interfaces for unexpected access.