Akira is a financially motivated ransomware operation active since at least 2023 and widely tracked under aliases including Gold Sahara, Howling Scorpius, Punk Spider, and Storm-1567. It is commonly described as a ransomware-as-a-service ecosystem with operators and affiliates, and has maintained substantial activity through 2026, with a particularly strong footprint in North America and sustained operations across Europe. Akira targets organizations across a broad range of sectors, with repeated victimization and reporting concentrated in the United States and Europe. Observed victims and sector reporting show activity against manufacturing, construction-related businesses, professional services, healthcare, hospitality, energy and utilities, and defense-related entities. Public reporting also links Akira to the compromise of a U.S. subsidiary of Swiss defense contractor Ruag, where the intrusion involved data theft and a ransom payment. Akira’s operations are characterized by data theft and extortion in addition to ransomware deployment. Reporting consistently associates the group with leak-site activity and threatened publication of stolen corporate information, indicating double-extortion as a standard operating model. Across 2026 reporting, Akira was repeatedly listed among the most active ransomware groups globally and regionally, including significant victim volumes in the United States, North America overall, and Europe. Observed tradecraft and case reporting show Akira-associated intrusions involving initial access, lateral movement, post-compromise discovery, and exfiltration. Broader ransomware trend reporting tied to Akira and peer groups highlights phishing and social engineering, abuse of valid accounts and remote access workflows, and exploitation of known vulnerabilities as common access paths. Akira-linked activity has also been associated in reporting with cloud tunnel tooling for persistence or remote access, although some individual attributions based on overlapping tradecraft remain low confidence and should not be treated as definitive for the group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
16 CVEs this actor has used in observed campaigns. 16 of them exploited in the wild.
CVE-2024-40766 (SonicWall SonicOS SSL VPN) : exploité massivement par Akira en 2024–2025
Additional exploited vulnerabilities include CVE-2023-20269 (Cisco ASA/FTD zero-day) ... MITRE ATT&CK TTP Matrix ... CVE-2023-20269 (Cisco)
and CVE-2020-3259, a memory disclosure vulnerability which can be used to retrieve credentials without authentication.
Akira have been observed to exploit Veeam vulnerabilities such as CVE-2023-27532 and CVE-2024-40711.
Akira have been observed to exploit Veeam vulnerabilities such as CVE-2023-27532 and CVE-2024-40711.
11 more CVEs tied to this actor tracked in Mallory.
147 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Secondary-tier ransomware group with focused European activity and stronger North American presence, especially targeting manufacturing and construction.
Conducting a ransomware attack and threatening to upload 104GB of stolen corporate data, including employee personal information, financials, contracts, NDAs, and client information.
Conducting a ransomware attack and claiming theft of 46GB of corporate data, including employee personal information, financials, contracts, NDAs, and client information.
Referenced as the ransomware group behind a prior breach of Ruag's U.S. subsidiary involving data theft and ransom payment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.