Akira Ransomware

Download 20+ pages of Akira's latest criminal behaviors, previous industry and geographic targets, exploited vulnerabilities, criminal associations, behaviors, and MITRE ATT&CK mappings.

Download Now

About This Threat Profile

First Identified: 2023

Threat Type:
Ransomware-as-a-Service (RaaS)

Extortion method:
Double extortion – combining the traditional ransomware extortion method (encryption) with exfiltration of victim’s sensitive data; the group threatens to leak the data via a data leak site if the ransom demand is not paid.

Most frequently targeted industry:

  • Industrials (Manufacturing)
  • Industrials (Construction & Engineering)
  • Consumer Cyclicals (Retail)

Most frequently targeted victim HQ Locations: North America

Select MITRE ATT&CK Mappings

    • Initial Access
      • Unauthorized logon to VPNs, exploiting external remote services, exploiting known vulnerabilities, social engineering, IABs (MITRE ATT&CK: T1078, T1133, T1190, T1199, T1566)
    • Persistence
      • Valid accounts, account manipulation, creating new accounts, browser extensions, server software components, boot or logon autostart execution (MITRE ATT&CK: T1078, T1098, T1136, T1176, T1505, T1547)
    • Lateral Movement
      • Abuse of remote services, tainted shared content, use alternate authentication material, lateral tool transferring (MITRE ATT&CK: T1021, T1080, T1550, T1563, T1570)

Description

Akira ransomware was first observed in March 2023 and operates as a ransomware-as-a-service (RaaS) using double extortion, where victim data is exfiltrated before systems are encrypted and threatened with publication if the ransom demand is not paid. The operation targets both Windows and Linux operating systems and has demanded ransoms ranging from $200,000 to $4 million. Akira has also been linked to the former Conti ransomware operation through similarities in its ransomware code and operational behaviors, as well as blockchain analysis identifying Akira ransom payments sent to Conti-affiliated cryptocurrency addresses.

Akira operators commonly gain initial access through compromised credentials and externally accessible remote services, particularly VPN infrastructure. The group has repeatedly targeted accounts without multi-factor authentication (MFA), including accounts used to access Cisco VPN products, and has obtained credentials or network access through initial access brokers (IABs). Akira has also exploited vulnerabilities affecting internet-facing infrastructure from vendors including Cisco, Fortinet, Veeam, VMware, and SonicWall. Additional initial access methods associated with the operation include spear phishing and password spraying.

The operation maintains several ransomware variants. In August 2023, researchers identified Megazord, a Rust-based variant that appends the .powerranges extension to encrypted files, while earlier Akira ransomware was written in Microsoft Visual C/C++ and used the .akira extension. Additional variants identified in 2023 include IQOJ and ZHQ, whose ransom notes directed victims to Akira’s TOR infrastructure. Akira later introduced Akira_v2, which has been used to target VMware ESXi environments, alongside platform-specific payloads capable of targeting Windows, Linux, VMware ESXi, and Nutanix AHV infrastructure.

Akira has repeatedly modified its ransomware following the release of publicly available decryption methods. In June 2023, Avast released a decryptor for an early Akira variant, after which the operators modified the encryptor and rendered the available decryptor ineffective. In March 2025, security researcher Yohanes Nugroho released another decryption method targeting Akira’s Linux variant by exploiting weaknesses in how encryption keys were generated from timestamp-based seeds. Akira remained active following the release, indicating the operators likely modified the ransomware again to prevent continued decryption.

Throughout 2025, Akira increasingly targeted edge infrastructure and remote access services. Between July and August, security vendors reported a significant increase in attacks against SonicWall SSL VPN devices. Initial reporting raised the possibility of zero-day exploitation, but SonicWall later assessed that the activity was likely associated with CVE-2024-40766. Subsequent research identified multiple methods through which Akira operators obtained valid SonicWall credentials, including access to configuration backups containing credential material, offline credential cracking, and the continued use of credentials migrated from Gen6 to Gen7 devices that had not been reset. Operators have also obtained MFA recovery codes and other authentication material from compromised environments, allowing them to bypass MFA and authenticate to SSL VPN portals using apparently legitimate accounts.

Following initial access, Akira operators rapidly conduct credential access, discovery, lateral movement, data exfiltration, and ransomware deployment. Observed tooling includes Impacket for SMB-based discovery and lateral movement; Mimikatz and Kerberoasting for credential access; AnyDesk and Atera for persistent remote access; WinRAR for data staging; WinSCP, FileZilla, and Rclone for exfiltration; and Ngrok for encrypted tunneling. Operators have also used PowerTool to exploit a vulnerable Zemana AntiMalware driver and terminate security-related processes. Akira has maintained access through perimeter devices using local accounts and cached sessions, including instances where access remained possible after vulnerable appliances were patched because associated credentials or sessions had not been reset.

The speed of Akira operations has become a significant characteristic of the group. In incidents analyzed by Halcyon, operators progressed from initial access through discovery, credential access, exfiltration, and ransomware deployment in less than four hours, with some attacks reaching encryption in under one hour. This compressed intrusion timeline significantly reduces the opportunity for defenders to identify and contain activity before ransomware deployment.

Akira has also optimized its encryption process for speed and recoverability. The ransomware uses intermittent encryption for large files, encrypting portions of each file rather than the entire file, and has reportedly configured encryption percentages as low as 1% to increase deployment speed while maintaining operational impact. During encryption of large files, Akira can create temporary .arika checkpoint files containing information about encryption progress, configuration, and encrypted key material. These files allow Akira’s decryptor to resume recovery of partially encrypted files when encryption is interrupted, reflecting continued development of both the ransomware and its associated recovery infrastructure.

Akira has continued expanding its capabilities alongside its targeting. By September 2025, the operation had reportedly received approximately $244 million in ransom payments. The group has also expanded its targeting of virtualized infrastructure beyond VMware ESXi, with operators observed encrypting Nutanix AHV virtual machine disk files. The combination of rapid intrusion timelines continued targeting of VPN infrastructure, credential-based access, exploitation of vulnerable internet-facing services, and expansion into additional virtualization platforms indicates Akira remains a capable and adaptable ransomware operation. It is very likely Akira will continue targeting exposed remote access infrastructure and vulnerable edge devices over the next 6–12 months.

DATE PUBLISHEDAugust 21, 2026
AUTHORBlackpoint Cyber

The 2AM Test

Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours

GET YOUR COPY