Akira is a Russian-language ransomware operation that emerged in April 2023 and has remained one of the most prolific financially motivated threat groups through 2026. It is widely tracked under the name Akira and has also been referred to as Gold Sahara, Howling Scorpius, Punk Spider, and Storm-1567. The operation is associated with a ransomware-as-a-service model or affiliate-based structure, with reporting also referring to Akira ransomware affiliates, operators, and crew. Akira conducts double-extortion intrusions, combining data theft with file encryption and threatening public release of stolen information to increase pressure on victims. The group has repeatedly targeted organizations in the United States and has also victimized entities in Europe and elsewhere. Reported victimology spans manufacturing, construction, professional services, transportation and logistics, technology, finance-related services, and other commercial sectors. Multiple 2026 reporting streams characterize Akira as one of the dominant or top-tier ransomware operations active in the global threat landscape. Akira has been linked to exploitation of internet-facing remote access and edge infrastructure, particularly VPN and SSL VPN appliances. Reporting has associated the group with campaigns involving SonicWall devices and with broader exploitation trends affecting products from vendors including Fortinet, SonicWall, Citrix, and Check Point. In some cases, investigators observed Akira intrusions involving compromised VPN accounts but could not conclusively determine whether access derived from direct appliance exploitation or from previously stolen credentials and other authentication artifacts. Observed Akira tradecraft includes credential abuse, remote access through exposed edge services, lateral movement across Windows environments, privilege escalation to domain administrator, internal reconnaissance, and large-scale data staging prior to ransomware deployment. The group has been observed abusing legitimate or dual-use tools to support operations, including remote administration software, file transfer utilities, port scanners, and Remote Desktop Protocol. Reporting has specifically linked Akira activity to the use of tools such as FileZilla for exfiltration support and MASSCAN for discovery of additional remote targets. In at least one documented intrusion, the operators maintained access for weeks, moved across multiple networks, staged substantial volumes of data for exfiltration, and then deployed ransomware broadly. Initial access associated with Akira has included social engineering and malware-enabled footholds as well as exploitation of perimeter technology. One reported case tied the group’s access to a user-driven download of SectopRAT after a fake verification prompt, after which the attackers expanded control, compromised privileged accounts, and prepared data theft before encryption. This reflects Akira’s willingness to blend commodity intrusion methods with hands-on-keyboard post-compromise activity. Akira is consistently described as pairing encryption with data theft rather than relying on encryption alone. Public victim-claim reporting through 2026 places the group among the most active ransomware brands by volume, with totals approaching 1,500 claimed victims overall and more than 300 claimed in the first half of 2026 alone. Despite fluctuations in quarterly rankings, Akira remains a significant ransomware threat with sustained operational tempo, broad victimology, and recurring use of edge-device and credential-based intrusion paths.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
16 CVEs this actor has used in observed campaigns. 16 of them exploited in the wild.
CVE-2024-40766 (SonicWall SonicOS SSL VPN) : exploité massivement par Akira en 2024–2025
Additional exploited vulnerabilities include CVE-2023-20269 (Cisco ASA/FTD zero-day) ... MITRE ATT&CK TTP Matrix ... CVE-2023-20269 (Cisco)
and CVE-2020-3259, a memory disclosure vulnerability which can be used to retrieve credentials without authentication.
Akira have been observed to exploit Veeam vulnerabilities such as CVE-2023-27532 and CVE-2024-40711.
Akira have been observed to exploit Veeam vulnerabilities such as CVE-2023-27532 and CVE-2024-40711.
11 more CVEs tied to this actor tracked in Mallory.
145 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Newer dominant ransomware group in the current ransomware landscape.
Conducting a ransomware attack and threatening to upload 30GB of stolen corporate data, including employee documents, client information, financials, contracts, and agreements.
Ransomware group noted as using double-extortion tactics by pairing encryption with data theft.
Referenced as part of prior intrusions involving SonicWall SSL VPN accounts; the content does not establish provenance of the credentials or focus primarily on Akira itself.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.