Akira — Ransomware Profile
Akira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.Also tracked as
GOLD SAHARA, PUNK SPIDER, Howling Scorpius
Tools & malware
- AdFind Network Reconnaissance
- Akira Ransomware
- Akira _v2 Ransomware
- LaZagne Credential Harvesting
- Megazord Backdoor
- Mimikatz Credential Harvesting
- PsExec Remote Execution
- Rclone Exfiltration Tool
Recent claimed victims
- Emerge2 Digital 2026-07-24
- Kruse Construction 2026-07-22
- University Sprinkler Systems 2026-07-22
- Novasport s.r.o. 2026-07-21
- Finer & Finer 2026-07-21
- McKeever , Varga & Senko 2026-07-20
- L&A Transport 2026-07-20
- Westcoast Communication Services 2026-07-17
- Nesco Bus Maintenance 2026-07-17
- Plumley Engineering 2026-07-16
- Pioneer Construction 2026-07-15
- Transworld Signs 2026-07-13
- Ironmark 2026-07-13
- Vandalia Rental 2026-07-10
- Wade's Dairy 2026-07-08
- RISE Architecture 2026-07-07
- Chisholm Persson & Ball 2026-07-07
- Excalibur Rentals 2026-07-07
- Edge Solutions | Stone Ridge Payments 2026-07-07
- Stone Ridge Payments 2026-07-07
- Refinery Hotel 2026-07-01
- Advanced Business Systems 2026-06-30
- About Todd Hamaker & Johnson 2026-06-30
- Precise Forms 2026-06-26
- JMS Southeast 2026-06-25
Vendor research
- SentinelOne SentinelOne
- GOLD SAHARA Secureworks
- Akira ransomware continues to evolve Cisco
- Conti and Akira: Chained Together Arctic Wolf
- #StopRansomware: Akira Ransomware CISA
- Threat Assessment: Howling Scorpius (Akira Ransomware) Palo Alto
- Secureworks. (n.d.). GOLD SAHARA Secureworks
- Tracking Adversaries: Akira, another descendent of Conti BushidoToken
- CrowdStrike. (n.d.). Punk Spider Crowdstrike