Akira is a financially motivated ransomware and data-extortion operation active since 2023 and commonly tracked as a ransomware-as-a-service ecosystem with multiple affiliates. Widely used aliases include Howling Scorpius, Gold Sahara, Storm-1567, and Punk Spider. The group is best known for double-extortion activity in which it steals data and then encrypts systems or threatens public disclosure to pressure victims into paying. Akira has targeted organizations across a broad range of sectors, including manufacturing, construction, professional services, telecommunications, transportation, hospitality, technology, financial services, and other business services, with victims observed in the United States, Europe, and elsewhere. Manufacturing and industrial environments have been recurrent targets. Reported tradecraft includes exploitation of internet-facing edge devices and VPN infrastructure for initial access, including sustained abuse of SonicWall SonicOS SSL VPN vulnerabilities such as CVE-2024-40766. Affiliates have also been observed obtaining footholds through social-engineering-driven malware delivery and then spending extended dwell time on victim networks before deploying ransomware. Post-compromise activity associated with Akira includes network reconnaissance and lateral movement using both native Windows capabilities and legitimate or dual-use tools. Observed tooling and techniques include remote access via RDP and remote management software, use of FTP software for data exfiltration, and network scanning with MASSCAN to identify additional reachable systems and services. The operation has also been linked to abuse of administrative shares and other common hands-on-keyboard intrusion behaviors. Like many mature ransomware crews, Akira frequently relies on legitimate or allowlisted tools to blend into enterprise environments and reduce detection. Akira’s operations consistently feature data theft and extortion claims alongside encryption, and public victim postings indicate routine threats to leak corporate records, financial documents, contracts, project materials, and employee or customer information. Reporting through 2026 indicates a decline in Akira’s relative activity and payment volume compared with some faster-growing competitors, but the group remained active and continued to claim victims regularly. Akira is best understood as an established criminal ransomware enterprise with an affiliate-driven operating model, broad sector targeting, and a demonstrated emphasis on exploiting perimeter weaknesses, conducting internal reconnaissance, exfiltrating data, and leveraging public leak pressure for monetization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
16 CVEs this actor has used in observed campaigns. 16 of them exploited in the wild.
CVE-2024-40766 (SonicWall SonicOS SSL VPN) : exploité massivement par Akira en 2024–2025
Additional exploited vulnerabilities include CVE-2023-20269 (Cisco ASA/FTD zero-day) ... MITRE ATT&CK TTP Matrix ... CVE-2023-20269 (Cisco)
and CVE-2020-3259, a memory disclosure vulnerability which can be used to retrieve credentials without authentication.
Akira have been observed to exploit Veeam vulnerabilities such as CVE-2023-27532 and CVE-2024-40711.
Akira have been observed to exploit Veeam vulnerabilities such as CVE-2023-27532 and CVE-2024-40711.
11 more CVEs tied to this actor tracked in Mallory.
145 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack and data extortion against Westcoast Communication Services, with claims of planned publication of 20GB of stolen corporate and employee data.
Conducting a ransomware attack and data extortion against Nesco Bus Maintenance, with claims of 26GB of stolen corporate data including employee personal information, contracts, customer information, payment details, and financial documents.
Ransomware group in decline during the quarter, historically reliant on mass exploitation campaigns, especially against SonicWall SSL VPN.
Conducting a ransomware attack and data extortion against Plumley Engineering, with claims of stealing 11GB of corporate data including client and employee personal information, project information, contracts, confidential files, and NDAs.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.