Overview

Platforms: Windows · Linux · VMware ESXi · Nutanix AHV · Hyper-V
Variants: Akira · Akira_v2 · Megazord
Extensions: .akira · .powerranges · .arika · .akiranew · .aki
ATT&CK software: AdFind · Akira · Akira_v2 · Megazord · LaZagne · Mimikatz · PsExec · Rclone · AnyDesk · LogMeIn · SharpDomainSpray
Initial access: Valid Accounts · External Remote Services
Top countries: US · CA · DE · GB · IT
Observed sectors: Manufacturing · Professional Services · Technology · Retail & E-Commerce · Financial Services
Tracked victims: 1,506

Victims

Manders CLAIMED
September 16, 2026 4 tracker sources
Blossomland Accounting CLAIMED
September 16, 2026 Professional Services 4 tracker sources
Professional Services organization.
Bee Maid Honey CLAIMED
September 16, 2026 Canada 4 tracker sources
Organization in Canada.
Southern California Telephone Company CLAIMED
September 15, 2026 United States Energy & Utilities 4 tracker sources
Energy & Utilities organization in United States.
Lazyboyz CLAIMED
September 15, 2026 Norway 4 tracker sources
Organization in Norway.
Show more victims (12)
Pilot Precision CLAIMED
September 15, 2026 Manufacturing 4 tracker sources
Manufacturing organization.
AK Stamping CLAIMED
September 10, 2026 United States Manufacturing 3 tracker sources
Manufacturing organization in United States.
Eagle Construction CLAIMED
September 10, 2026 United States Construction 3 tracker sources
Construction organization in United States.
George Cameron Nash CLAIMED
September 10, 2026 United States Professional Services 3 tracker sources
Professional Services organization in United States.
Kyodo USA CLAIMED
September 9, 2026 United States Manufacturing 3 tracker sources
Manufacturing organization in United States.
Brentwood Country Club CLAIMED
September 8, 2026 United States Hospitality 3 tracker sources
Hospitality organization in United States.
CreateASoft CLAIMED
September 8, 2026 Technology 3 tracker sources
Technology organization.
Brent Electric CLAIMED
September 8, 2026 United Kingdom Energy & Utilities 3 tracker sources
Energy & Utilities organization in United Kingdom.
Stransky Heiz-Mess-Regeltechnik GmbH CLAIMED
September 4, 2026 Germany Manufacturing 3 tracker sources
Manufacturing organization in Germany.
Worrell CLAIMED
September 4, 2026 3 tracker sources
ScrubaDub Auto Wash Centers CLAIMED
September 2, 2026 United States Retail & E-Commerce 3 tracker sources
Retail & E-Commerce organization in United States.
Algra Group CLAIMED
September 2, 2026 Switzerland 3 tracker sources
Organization in Switzerland.

Operational Activity

Recent Observations

Initial access via compromised VPN credentials
Akira affiliates leverage compromised credentials for externally exposed VPN infrastructure, such as SonicWall SSL VPNs, particularly targeting services lacking multi-factor authentication. Vulnerabilities such as CVE-2024-40766 have also been exploited to facilitate this access.
Safe Mode anti-EDR deployment
August 4, 2026
Affiliates have been observed rebooting compromised Windows systems into Safe Mode with Networking to suppress endpoint detection and response (EDR) agents and security software like Microsoft Defender. In observed cases, attackers also added remote access tools like AnyDesk to the Safe Mode service list to maintain persistence during the reboot.
Nutanix AHV encryption
June 2025
Akira ransomware has been observed targeting and encrypting virtual machine disk files within Nutanix Acropolis Hypervisor (AHV) environments, expanding their virtualization-based attack surface beyond VMware ESXi and Hyper-V.
Credential access via LSASS dumping
Actors have been observed utilizing legitimate system tools or specialized credential dumping utilities to extract credentials from the Local Security Authority Subsystem Service (LSASS) process.
Data exfiltration via cloud storage tools
To facilitate data exfiltration, affiliates deploy legitimate cloud storage synchronization and transfer tools, including Rclone, WinSCP, and FileZilla, to move sensitive data to actor-controlled cloud storage services.

TTPs

ATT&CK coverage: 14 techniques
T1078 Valid Accounts
VERIFIED
Akira utilizes valid account information, specifically compromised VPN credentials, to establish initial access.
T1133 External Remote Services
VERIFIED
Actors leverage compromised VPN accounts and externally exposed remote-access infrastructure for initial network entry.
T1021.001 Remote Desktop Protocol
VERIFIED
RDP is frequently used by Akira operators for lateral movement and post-compromise activity.
Show more TTPs (11)
T1219 Remote Access Software
VERIFIED
Legitimate remote access software, including AnyDesk, TeamViewer, and RustDesk, is used for command and control.
T1059.001 PowerShell
VERIFIED
PowerShell is used for various post-exploitation tasks, including credential harvesting and system manipulation.
T1018 Remote System Discovery
VERIFIED
Network scanning tools are used to identify and map reachable systems within the victim network.
T1482 Domain Trust Discovery
VERIFIED
Tools such as AdFind are utilized to perform Active Directory enumeration and map domain trust relationships.
T1560.001 Archive via Utility
VERIFIED
WinRAR and other archiving utilities are used to stage data prior to exfiltration.
T1567.002 Exfiltration to Cloud Storage
VERIFIED
Rclone and other tools are used to exfiltrate data to cloud storage services.
T1562.001 Impair Defenses: Disable or Modify Tools
VERIFIED
Actors disable or uninstall security software, including antivirus and EDR, prior to encryption.
T1558 Steal or Forge Kerberos Tickets
VERIFIED
Credential access is achieved by targeting Kerberos tickets.
T1490 Inhibit System Recovery
VERIFIED
Volume Shadow Copies are deleted to hinder recovery and facilitate the impact of encryption.
T1486 Data Encrypted for Impact
VERIFIED
Akira ransomware encrypts victim files as part of its double-extortion operation.
T1562.010 Impair Defenses: Downgrade Attack Vectors
VERIFIED
Actors have been observed booting systems into Safe Mode with Networking to evade endpoint security detection.

CVEs

Akira ransomware affiliates have been observed gaining initial access through SonicWall SSLVPN accounts on devices running firmware affected by CVE-2024-40766. Direct exploitation of CVE-2024-40766 was not definitively confirmed in the investigated intrusions.
Associated since: September 2024
Cisco Talos identified exploitation of this vulnerability in the Cisco ASA/FTD Remote Access VPN in campaigns attributed to the Akira ransomware group.
Associated since: August 2023
Akira ransomware affiliates have been observed exploiting this vulnerability in Cisco products to gain initial access.
Associated since: April 2024

Infrastructure

Leak site
Tor-based data leak site used by the Akira ransomware group to publish victim data.
ONLINE
Last checked: September 19, 2026

Attribution

GOLD SAHARA VERIFIED
Vendor tracking name
Adversary group associated with the operation and deployment of Akira ransomware.
PUNK SPIDER VERIFIED
Vendor tracking name
Adversary group associated with the development and maintenance of Akira ransomware.
Howling Scorpius VERIFIED
Vendor tracking name
Adversary group behind the Akira ransomware-as-a-service operation.
Storm-1567 VERIFIED
Vendor tracking name
Threat actor identified by Microsoft as the operator behind Akira ransomware.

Relationships

Conti PROBABLE
Operator overlap
Operational lineage and technical similarities suggest links between Akira and the defunct Conti syndicate.
STAC5881 VERIFIED
Ransomware usage
Sophos reported that STAC5881 intrusions using the Veeam vulnerability deployed multiple ransomware payloads, including Akira. The report explicitly identifies Akira as one of the ransomware families observed in this actor/cluster's cases.
Scattered Spider PROBABLE
Ransomware usage
Scattered Spider has been reported deploying Akira ransomware as part of its use of multiple ransomware families. This supports an operational association with Akira but does not establish a permanent or exclusive Akira affiliate relationship.

Affiliates

No affiliate information available.

Timeline

2025-09-01
Reported ransom proceeds exceed $244 million
An updated joint government advisory reported that Akira ransomware proceeds had reached approximately $244.17 million by late September 2025.
2025-06-01
Nutanix AHV targeting documented
Documentation confirmed Akira had extended its virtualization targeting to include the encryption of Nutanix AHV virtual machine disk files.
2024-04-18
Joint international advisory published
The FBI, CISA, Europol EC3, and NCSC-NL released a joint advisory noting that Akira had impacted over 250 organizations.
Show more events (3)
2023-08-01
Megazord encryptor deployment observed
Akira affiliates began utilizing the Rust-based Megazord encryptor in addition to the group's original ransomware codebase.
2023-04-01
Linux and VMware ESXi targeting documented
Akira expanded its capabilities to include a Linux-based variant specifically targeting VMware ESXi virtualized environments.
2023-03-01
Akira ransomware operation first observed
Akira emerged as a ransomware-as-a-service operation, characterized by double-extortion tactics.

Sources