Akira is a ransomware-as-a-service operation that emerged in 2023 and became a prominent double-extortion threat targeting organizations across multiple sectors, with especially heavy activity against manufacturing, construction, retail, technology, healthcare, finance, education, and other enterprise environments in North America and Europe. The operation is widely tracked as Akira and has also been associated with aliases including Storm-1567, Howling Scorpius, PUNK SPIDER, and MITRE group identifier G1024. Reporting has noted suspected ties to former Conti ecosystem members based on code and operational overlap.
Akira conducts intrusions by obtaining network access through compromised VPN credentials, exploitation of internet-facing edge devices and SSL VPN appliances, spearphishing, brute-force activity against remote access services, and access purchased from initial access brokers. The group has repeatedly been associated with exploitation of vulnerabilities in products from vendors such as Cisco, SonicWall, Fortinet, Citrix, and Check Point, and multiple investigations have highlighted Akira activity against environments lacking multi-factor authentication on VPN accounts. Campaigns have also been observed using SEO poisoning and trojanized software installers that led to follow-on malware deployment before Akira encryption.
Once inside a victim environment, Akira commonly establishes persistence through newly created privileged accounts and deployment of remote access tools. It performs reconnaissance with network scanners, Active Directory enumeration utilities, PowerShell, and native administrative tooling. Credential theft is a core part of its tradecraft and has included harvesting from LSASS, Active Directory databases, browser stores, backup software, and other enterprise credential sources using tools such as Mimikatz, DonPAPI, LaZagne, PCHunter, NirSoft utilities, and Veeam-focused credential extraction methods.
Akira operators move laterally through enterprise networks using RDP, SMB administrative shares, PsExec, WMI, WMIC, Impacket, and SSH, including movement into virtualization and backup infrastructure. The group has been repeatedly observed targeting backup systems and recovery mechanisms, terminating database, backup, and security services, deleting shadow copies, and otherwise inhibiting restoration before encryption. Data theft typically precedes encryption, with archives staged and exfiltrated using common transfer tools and cloud or file-transfer services. This supports Akira’s double-extortion model, in which stolen data is used to pressure victims in addition to system encryption.
The malware family has evolved into multiple variants. Akira initially used a Windows encryptor written in C++, later introduced a Rust-based variant known as Megazord, and expanded to Linux and ESXi environments. Reporting also describes Akira activity against Nutanix AHV virtual machine disks. The operation is therefore capable of impacting Windows endpoints and servers as well as Linux-based virtualization infrastructure. Akira’s encryptors use hybrid cryptography and are accompanied by ransom notes directing victims to negotiation and leak infrastructure.
Akira has also been associated with defense-evasion techniques including disabling Windows Defender, clearing event logs, covert tunneling, command obfuscation, and bring-your-own-vulnerable-driver activity to impair endpoint protections. Incident reporting has documented use of vulnerable drivers, remote administration tools, reverse tunnels, and cloud tunneling services during post-compromise operations. In several investigations, Akira deployment followed a relatively short dwell time after initial access, though broader reporting indicates the group often spends time on stealth, staging, credential access, exfiltration, and lateral expansion before encryption.
Akira is one of the most active ransomware groups of the mid-2020s and has been linked to hundreds of victims and substantial illicit revenue. Its operational pattern reflects a mature RaaS ecosystem combining credential-driven intrusion, edge-device exploitation, broad post-exploitation capability, data exfiltration, and enterprise-wide encryption across both traditional Windows networks and virtualized infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Cisco is aware of reports of this vulnerability being actively exploited in the wild. Further information can be found in Cisco’s blog relating to this. https://blogs.cisco.com/security/akira-ransomware-targeting-vpns-without-multi-factor-authentication
SonicWall в обновлении от 6 августа 2025 уточнил: атаки связаны с CVE-2024-40766 - Improper Access Control (CWE-284, CVSS 9.8). | Akira ransomware - одна из активных групп... В июле-августе 2025 года Huntress, Arctic Wolf и Mandiant зафиксировали около 40 инцидентов с Akira ransomware, нацеленных на Gen 7 SonicWall firewalls
Additional exploited vulnerabilities include ... CVE-2023-48788 (FortiClientEMS SQL injection) ... | Akira is a ransomware-as-a-service (RaaS) group that emerged in March 2023... Akira initially coded its ransomware in C++ for Windows... but introduced a new Rust-based variant in August 2023 (dubbed 'Megazord')... The group currently operates four primary variants: Akira, Megazord, Akira Linux, and Akira_v2.
and CVE-2020-3259, a memory disclosure vulnerability which can be used to retrieve credentials without authentication. | Unmasking Akira: the ransomware tactics you can’t afford to ignore... Akira focuses on being a double extortion group... first stealing data, then encrypting it, demanding payment to prevent public leaks and restore systems.
Akira have been observed to exploit Veeam vulnerabilities such as CVE-2023-27532 and CVE-2024-40711. | Unmasking Akira: the ransomware tactics you can’t afford to ignore... Akira focuses on being a double extortion group... first stealing data, then encrypting it, demanding payment to prevent public leaks and restore systems.
Akira have been observed to exploit Veeam vulnerabilities such as CVE-2023-27532 and CVE-2024-40711. | Unmasking Akira: the ransomware tactics you can’t afford to ignore... Akira focuses on being a double extortion group... first stealing data, then encrypting it, demanding payment to prevent public leaks and restore systems.
Additional exploited vulnerabilities include ... CVE-2024-37085 (VMware ESXi authentication bypass) ... | Akira is a ransomware-as-a-service (RaaS) group that emerged in March 2023... Akira initially coded its ransomware in C++ for Windows... but introduced a new Rust-based variant in August 2023 (dubbed 'Megazord')... The group currently operates four primary variants: Akira, Megazord, Akira Linux, and Akira_v2.
ReliaQuest identified what we assess with medium confidence to be the first known exploitation of this vulnerability, spanning multiple environments between February and March 2026... CVE-2024-12802 is an authentication bypass vulnerability in SonicWall appliances that reduces VPN security to single-factor authentication... On Gen6 devices, the firmware patch alone doesn’t remediate the vulnerability. Six additional manual reconfiguration steps are required.
In Q4 2023, Kroll identified an uptick in engagements involving Akira ransomware, a trend that has continued into 2024... Shortly after privilege escalation, Akira ransomware was deployed to encrypt systems.
CVE-2023-48365: Qlik Sense Enterprise HTTP Tunneling RCE (CVSS 9.9)
CVE-2025-23006: SonicWall SMA 1000 Pre-Auth Deserialization RCE (CVSS 9.8)
CVE-2024-21762: Fortinet FortiOS SSL VPN Out-of-Bounds Write RCE (CVSS 9.8)
CVE-2023-27997: Fortinet FortiOS SSL VPN Heap Buffer Overflow RCE - XORtigate (CVSS 9.8)
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Figure 3 below represents the total number of victims claimed by The Gentlemen in 2025 compared to both Qilin and Akira, tracked by Unit 42 as Howling Scorpius.
The crown jewel of their operations is the use of the ransomware that gives them their name: Akira ... It retains various capabilities such as controlling disk drives, managing running processes, multi-threaded operation, and, of course, encrypting files and writing ransom notes on the victim’s devices.
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
In July 2024, Microsoft also linked the Storm-1175 threat group, along with three other cybercrime gangs, to Black Basta and Akira ransomware attacks that exploited a VMware ESXi authentication-bypass flaw.
"...the use of this technique has led to Akira and Black Basta ransomware deployments."
"...the use of this technique has led to Akira and Black Basta ransomware deployments."
10 distinct techniques documented for this family, organized by ATT&CK tactic.
288 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newer dominant ransomware family/group mentioned as part of the current ransomware landscape.
A ransomware group observed exploiting VPN and edge-device vulnerabilities to gain initial access to victim environments.
Ransomware deployed against retail targets in the broader campaign context.
Ransomware group mentioned in sector specialization discussion, particularly targeting manufacturing and construction.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.