Ako, also referred to as Razny in some reporting, was a ransomware operation active during the broader shift of the ransomware ecosystem toward double-extortion and public leak-site pressure. The group conducted file encryption and also stole victim data, using separate demands for decryption and for deletion of exfiltrated files. This places Ako among the ransomware actors that monetized both operational disruption and the threat of public exposure. Ako operated a leak site and was publicly identified as one of the groups using stolen unencrypted files to extort victims. Reporting on victim negotiations indicated that the group distinguished between payment for a decryptor and payment intended to suppress release or retention of stolen data, demonstrating a data-theft-extortion model alongside encryption. Ako was also listed among ransomware operations that actively leaked victim files on blogs during the expansion of naming-and-shaming tactics across the ransomware landscape. The operation appeared to shut down around the period of heightened pressure on ransomware actors following the Colonial Pipeline incident. Contemporary reporting described Ako/Razny as one of the smaller ransomware groups that appeared to cease public operations, although this did not establish that the operators permanently exited cybercrime. No high-confidence attribution to a nation state is supported. Ako is best characterized as a financially motivated cybercriminal ransomware group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as another ransomware operation whose Tor sites went offline.
Smaller ransomware group that appears to have voluntarily shut down amid pressure on the ransomware ecosystem.
Mentioned only as one of several other ransomware operations using leak-site or stolen-data extortion tactics.
Ransomware group described as using double extortion with separate payment demands for decryption and deletion of stolen files.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.