Akira Topped Sophos Ransomware Cases in 2024, Peaked at 17% of August Detections Amid Veeam Exploits

No ransomware group did more to fill the void left by disrupted operations in 2024 than Akira. The Sophos Annual Threat Report Appendix, published April 2025, identifies Akira as the most frequently encountered ransomware family across all 2024 MDR and IR cases — peaking at 17% of all ransomware detections in August, roughly double its share from the first half of the year.

Absorbing LockBit's Displaced Affiliates

Following law enforcement actions that disrupted LockBit in early 2024, Akira absorbed displaced affiliates and expanded its attack tempo. Sophos documented Akira-linked affiliates also deploying Fog, Frag, and Megazord variants — indicating a fluid affiliate ecosystem rather than exclusive loyalty to a single payload.

One activity cluster tracked internally as STAC5881 exploited CVE-2024-40711, a critical RCE flaw in Veeam Backup & Replication, creating identically named local administrator accounts (named "point") on compromised systems. Depending on which affiliate executed the final stage, the payload was Akira, Fog, or the newly observed junk-gun ransomware Frag, obtained from underground markets for approximately $375.

The Constant: VPN Without MFA

"Typically, Akira's targets had VPNs with no multifactor authentication, or had misconfigured VPN gateways that allowed the attackers to gain access with stolen credentials or brute force attacks," Sophos noted.

By year-end Akira still held roughly 9% of Sophos ransomware detections — sustained market share even as newer families competed for affiliates. Key mitigations: patch CVE-2024-40711 immediately, enforce phishing-resistant MFA on all VPN endpoints, monitor for unexpected local administrator account creation, and isolate backup infrastructure.

Read the full analysis on IntelFusions