Akira — Ransomware Profile
Akira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
GOLD SAHARA, PUNK SPIDER, Howling Scorpius, Storm-1567
IntelFusions coverage (15)
- LockBit leads a four-fold jump in Dutch leak-site listings 2026-09-05 · Cyber Incidents
- Settra quietly became one of the busiest extortion crews 2026-09-04 · Ransomware
- New ransomware crew Za Woo opens with 10 German victims 2026-08-30 · Ransomware
- Veeam bug wrote backup credentials into plain text logs 2026-08-26 · Vulnerabilities
- New crew Storm goes after US clinics, banks and factories 2026-08-25 · Ransomware
- Akira reboots PCs into Safe Mode to blind security tools 2026-08-19 · Ransomware
- Ransomware crews can hide their tracks in ESX logs 2026-08-07 · Ransomware
- Hackers poison Bing search results to drop Akira ransomware on companies 2026-06-29 · Ransomware
- Ransomware gang claims to hit German submarine builder Thyssenkrupp 2026-06-28 · Ransomware
- Newer ransomware crews claim diagnostics maker Hologic and an Australian fire service 2026-06-28 · Ransomware
- New ransomware crew The Gentlemen claims 20 victims in one week 2026-06-12 · Ransomware
- NightSpire: The Rbfs Rebrand That Went From Data Theft to Double Extortion in Weeks 2026-02-16 · Ransomware
- Akira Topped Sophos Ransomware Cases in 2024, Peaked at 17% of August Detections Amid Veeam Exploits 2026-02-16 · Ransomware
- From Conti Code to ESXi Servers: SentinelOne Decodes Akira's Cross-Platform Ransomware Evolution 2026-02-16 · Ransomware
- Akira Ransomware Targets Cisco VPNs Without MFA: Sophos Documents Over a Dozen Incidents 2026-02-16 · Ransomware
Tools & malware
- AdFind Network Reconnaissance
- Advanced IP Scanner tool
- Akira Ransomware
- Akira _v2 Ransomware
- AnyDesk tool
- Cloudflare Tunnel tool
- FileZilla tool
- LaZagne Credential Harvesting
- Megazord Backdoor
- Mimikatz Credential Harvesting
- MobaXterm tool
- Ngrok tool
- PCHunter64 tool
- PowerTool tool
- PsExec Remote Execution
- Rclone Exfiltration Tool
- RustDesk tool
- SoftPerfect Network Scanner tool
- WinRAR tool
- WinSCP tool
Recent claimed victims
- Brent Electric 2026-09-08
- Brentwood Country Club 2026-09-08
- CreateASoft 2026-09-08
- Worrell 2026-09-04
- Stransky Heiz-Mess-Regeltechnik GmbH 2026-09-04
- PennFab 2026-09-02
- ScrubaDub Auto Wash Centers 2026-09-02
- Algra Group 2026-09-02
- Flex1 2026-09-01
- BYK Construction 2026-09-01
- Congressional Iron Works 2026-09-01
- KFZ-MEISTERBETRIEB JOST GmbH 2026-08-31
- Gale Credit Union 2026-08-31
- WEMS 2026-08-31
- BEPeterson 2026-08-28
- JRT Mechanical 2026-08-28
- Alumax 2026-08-28
- Cetylite 2026-08-27
- Seabrook Island 2026-08-27
- CGP MEP 2026-08-27
- Gill Rock Drill 2026-08-26
- Oral and Maxillofacial Surgery 2026-08-26
- PA-ID 2026-08-26
- WINTER Ingenieure 2026-08-25
- Davis & Ferber 2026-08-25
Vendor research
- GOLD SAHARA Secureworks
- the full attack chain and indicators Huntress
- SentinelOne SentinelOne
- Conti and Akira: Chained Together Arctic Wolf
- Tracking Adversaries: Akira, another descendent of Conti BushidoToken
- #StopRansomware: Akira Ransomware CISA
- Secureworks. (n.d.). GOLD SAHARA Secureworks
- Threat Assessment: Howling Scorpius (Akira Ransomware) Palo Alto
- CrowdStrike. (n.d.). Punk Spider Crowdstrike
- Akira ransomware continues to evolve Cisco