Akira is a financially motivated ransomware and data-extortion operation, also tracked as Gold Sahara, Howling Scorpius, Punk Spider, and Storm-1567. The group has targeted organizations internationally, with a substantial concentration of reported victims in the United States, spanning manufacturing, construction, financial services, information technology, health-related manufacturing, and hospitality. Akira operates a leak site and routinely threatens publication of purportedly stolen corporate data to pressure victims. Reported victim listings commonly claim theft of employee and customer information, financial records, contracts, project data, and other confidential business material; individual victim claims and alleged data volumes are not necessarily independently verified. Akira has been associated with use of cloud-storage services and Rclone for data exfiltration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
17 CVEs this actor has used in observed campaigns. 17 of them exploited in the wild.
CVE-2024-40766 (SonicWall SonicOS SSL VPN) : exploité massivement par Akira en 2024–2025
Additional exploited vulnerabilities include CVE-2023-20269 (Cisco ASA/FTD zero-day) ... MITRE ATT&CK TTP Matrix ... CVE-2023-20269 (Cisco)
and CVE-2020-3259, a memory disclosure vulnerability which can be used to retrieve credentials without authentication.
Akira have been observed to exploit Veeam vulnerabilities such as CVE-2023-27532 and CVE-2024-40711.
Akira have been observed to exploit Veeam vulnerabilities such as CVE-2023-27532 and CVE-2024-40711.
12 more CVEs tied to this actor tracked in Mallory.
183 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed ransomware attack against PennFab, a Pennsylvania steel-manufacturing company, with a threat to publish approximately 40 GB of purported corporate, employee, client, contractual, and financial data.
Conducted a ransomware attack against Algra Group and claimed it would upload corporate data, including employee personal information, client and partner information, contacts, agreements, financial records, and NDAs.
Claimed ransomware attack against ScrubaDub Auto Wash Centers, with a stated intent to publish corporate data including employee personal information, customer information, financial records, and payment details.
Recorded 12 ransomware claims during the reporting week; its activity has been documented for several months.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.