Overview
Platforms:
Windows · Linux · VMware ESXi · Nutanix AHV · Hyper-V
Variants:
Akira · Akira_v2 · Megazord
Extensions:
.akira · .powerranges · .arika · .akiranew · .aki
ATT&CK software:
AdFind · Akira · Akira_v2 · Megazord · LaZagne · Mimikatz · PsExec · Rclone · AnyDesk · LogMeIn · SharpDomainSpray
Initial access:
Valid Accounts · External Remote Services
Top countries:
US · CA · DE · GB · IT
Observed sectors:
Manufacturing · Professional Services · Technology · Retail & E-Commerce · Financial Services
Tracked victims:
1,506
Victims
Manders
CLAIMED
Blossomland Accounting
CLAIMED
Professional Services organization.
Bee Maid Honey
CLAIMED
Organization in Canada.
Southern California Telephone Company
CLAIMED
Energy & Utilities organization in United States.
Lazyboyz
CLAIMED
Organization in Norway.
Show more victims (12)
Pilot Precision
CLAIMED
Manufacturing organization.
AK Stamping
CLAIMED
Manufacturing organization in United States.
Eagle Construction
CLAIMED
Construction organization in United States.
George Cameron Nash
CLAIMED
Professional Services organization in United States.
Kyodo USA
CLAIMED
Manufacturing organization in United States.
Brentwood Country Club
CLAIMED
Hospitality organization in United States.
CreateASoft
CLAIMED
Technology organization.
Brent Electric
CLAIMED
Energy & Utilities organization in United Kingdom.
Stransky Heiz-Mess-Regeltechnik GmbH
CLAIMED
Manufacturing organization in Germany.
Worrell
CLAIMED
ScrubaDub Auto Wash Centers
CLAIMED
Retail & E-Commerce organization in United States.
Algra Group
CLAIMED
Organization in Switzerland.
Operational Activity
Recent Observations
Initial access via compromised VPN credentials
Akira affiliates leverage compromised credentials for externally exposed VPN infrastructure, such as SonicWall SSL VPNs, particularly targeting services lacking multi-factor authentication. Vulnerabilities such as CVE-2024-40766 have also been exploited to facilitate this access.
Safe Mode anti-EDR deployment
August 4, 2026
Affiliates have been observed rebooting compromised Windows systems into Safe Mode with Networking to suppress endpoint detection and response (EDR) agents and security software like Microsoft Defender. In observed cases, attackers also added remote access tools like AnyDesk to the Safe Mode service list to maintain persistence during the reboot.
Nutanix AHV encryption
June 2025
Akira ransomware has been observed targeting and encrypting virtual machine disk files within Nutanix Acropolis Hypervisor (AHV) environments, expanding their virtualization-based attack surface beyond VMware ESXi and Hyper-V.
Credential access via LSASS dumping
Actors have been observed utilizing legitimate system tools or specialized credential dumping utilities to extract credentials from the Local Security Authority Subsystem Service (LSASS) process.
Data exfiltration via cloud storage tools
To facilitate data exfiltration, affiliates deploy legitimate cloud storage synchronization and transfer tools, including Rclone, WinSCP, and FileZilla, to move sensitive data to actor-controlled cloud storage services.
TTPs
ATT&CK coverage:
14 techniques
T1078
Valid Accounts
VERIFIEDAkira utilizes valid account information, specifically compromised VPN credentials, to establish initial access.
T1133
External Remote Services
VERIFIEDActors leverage compromised VPN accounts and externally exposed remote-access infrastructure for initial network entry.
T1021.001
Remote Desktop Protocol
VERIFIEDRDP is frequently used by Akira operators for lateral movement and post-compromise activity.
Show more TTPs (11)
T1219
Remote Access Software
VERIFIEDLegitimate remote access software, including AnyDesk, TeamViewer, and RustDesk, is used for command and control.
T1059.001
PowerShell
VERIFIEDPowerShell is used for various post-exploitation tasks, including credential harvesting and system manipulation.
T1018
Remote System Discovery
VERIFIEDNetwork scanning tools are used to identify and map reachable systems within the victim network.
T1482
Domain Trust Discovery
VERIFIEDTools such as AdFind are utilized to perform Active Directory enumeration and map domain trust relationships.
T1560.001
Archive via Utility
VERIFIEDWinRAR and other archiving utilities are used to stage data prior to exfiltration.
T1567.002
Exfiltration to Cloud Storage
VERIFIEDRclone and other tools are used to exfiltrate data to cloud storage services.
T1562.001
Impair Defenses: Disable or Modify Tools
VERIFIEDActors disable or uninstall security software, including antivirus and EDR, prior to encryption.
T1558
Steal or Forge Kerberos Tickets
VERIFIEDCredential access is achieved by targeting Kerberos tickets.
T1490
Inhibit System Recovery
VERIFIEDVolume Shadow Copies are deleted to hinder recovery and facilitate the impact of encryption.
T1486
Data Encrypted for Impact
VERIFIEDAkira ransomware encrypts victim files as part of its double-extortion operation.
T1562.010
Impair Defenses: Downgrade Attack Vectors
VERIFIEDActors have been observed booting systems into Safe Mode with Networking to evade endpoint security detection.
CVEs
Akira ransomware affiliates have been observed gaining initial access through SonicWall SSLVPN accounts on devices running firmware affected by CVE-2024-40766. Direct exploitation of CVE-2024-40766 was not definitively confirmed in the investigated intrusions.
Associated since:
September 2024
Cisco Talos identified exploitation of this vulnerability in the Cisco ASA/FTD Remote Access VPN in campaigns attributed to the Akira ransomware group.
Associated since:
August 2023
Akira ransomware affiliates have been observed exploiting this vulnerability in Cisco products to gain initial access.
Associated since:
April 2024
Infrastructure
Leak site
Tor-based data leak site used by the Akira ransomware group to publish victim data.
ONLINE
Last checked:
September 19, 2026
Attribution
GOLD SAHARA
VERIFIED
Vendor tracking name
Adversary group associated with the operation and deployment of Akira ransomware.
PUNK SPIDER
VERIFIED
Vendor tracking name
Adversary group associated with the development and maintenance of Akira ransomware.
Howling Scorpius
VERIFIED
Vendor tracking name
Adversary group behind the Akira ransomware-as-a-service operation.
Storm-1567
VERIFIED
Vendor tracking name
Threat actor identified by Microsoft as the operator behind Akira ransomware.
Relationships
Conti
PROBABLE
Operator overlap
Operational lineage and technical similarities suggest links between Akira and the defunct Conti syndicate.
STAC5881
VERIFIED
Ransomware usage
Sophos reported that STAC5881 intrusions using the Veeam vulnerability deployed multiple ransomware payloads, including Akira. The report explicitly identifies Akira as one of the ransomware families observed in this actor/cluster's cases.
Scattered Spider
PROBABLE
Ransomware usage
Scattered Spider has been reported deploying Akira ransomware as part of its use of multiple ransomware families. This supports an operational association with Akira but does not establish a permanent or exclusive Akira affiliate relationship.
Affiliates
No affiliate information available.
Timeline
2025-09-01
Reported ransom proceeds exceed $244 million
An updated joint government advisory reported that Akira ransomware proceeds had reached approximately $244.17 million by late September 2025.
2025-06-01
Nutanix AHV targeting documented
Documentation confirmed Akira had extended its virtualization targeting to include the encryption of Nutanix AHV virtual machine disk files.
2024-04-18
Joint international advisory published
The FBI, CISA, Europol EC3, and NCSC-NL released a joint advisory noting that Akira had impacted over 250 organizations.
Show more events (3)
2023-08-01
Megazord encryptor deployment observed
Akira affiliates began utilizing the Rust-based Megazord encryptor in addition to the group's original ransomware codebase.
2023-04-01
Linux and VMware ESXi targeting documented
Akira expanded its capabilities to include a Linux-based variant specifically targeting VMware ESXi virtualized environments.
2023-03-01
Akira ransomware operation first observed
Akira emerged as a ransomware-as-a-service operation, characterized by double-extortion tactics.
Sources
Threat Assessment: Howling Scorpius (Akira Ransomware)
Palo Alto Networks Unit 42
Show more sources (18)
Akira Ransomware: Highlighting New Tactics and Techniques
Palo Alto Networks Unit 42
Akira ransomware targeting Nutanix AHV
Field Effect
Punk Spider Adversary Profile
CrowdStrike
Conti and Akira: Chained Together
Arctic Wolf Labs
Threat Actor Groups Tracked by Palo Alto Networks Unit 42
Palo Alto Networks Unit 42
Akira Ransomware - Threat Actor
Fortinet FortiGuard Labs
Scattered Spider
Halcyon