Akira is a ransomware operation active since 2023 that has become one of the more prominent extortion threats affecting enterprise environments. It is associated with double-extortion activity, combining file encryption with data theft and threats to publish stolen information. Reporting through 2025 and 2026 places Akira among the more active ransomware groups globally, with repeated victimization across manufacturing, construction, healthcare, energy, education, financial services, retail, and other mid-market and enterprise sectors.
Akira has been repeatedly linked to intrusions that begin through compromised remote access infrastructure and exposed edge devices, especially VPN and firewall products. High-confidence reporting ties the group to exploitation of authentication-bypass and other vulnerabilities affecting SonicWall devices, and broader reporting also places Akira among ransomware actors abusing weaknesses in products from vendors such as Fortinet, Citrix, and Check Point to gain an initial foothold. In addition to vulnerability exploitation, Akira has been discussed in the broader ransomware ecosystem alongside phishing, identity abuse, stolen credentials, and remote access compromise as common entry paths, but direct malware-specific delivery evidence is strongest for edge-device exploitation.
Operationally, Akira intrusions are associated with lateral movement, post-compromise network expansion, and exfiltration prior to extortion. Public reporting also links Akira tradecraft to the use of tunneling utilities in some campaigns, although not every such observation is attributed with high confidence. Akira has been observed targeting Windows environments and VMware ESXi, and U.S. government reporting in late 2025 stated that the operation had expanded to encrypt Nutanix virtualization platforms as well. The group has accumulated substantial ransom proceeds since its emergence and remains a significant threat to organizations that expose remote access services or fail to harden perimeter infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Update 1: Nach neuen Erkenntnissen von SonicWall sei für die Vorfälle mit hoher Wahrscheinlichkeit keine neue Zero-Day-Schwachstelle ausschlaggebend gewesen, sondern die bereits bekannte Sicherheitslücke CVE-2024-40766. | Anschließend konnten die Täter (Akira) Ransomware ausrollen und weiterführende Angriffe (Lateral Movement) initiieren.
Cisco is aware of reports of this vulnerability being actively exploited in the wild. Further information can be found in Cisco’s blog relating to this. https://blogs.cisco.com/security/akira-ransomware-targeting-vpns-without-multi-factor-authentication
Additional exploited vulnerabilities include ... CVE-2023-48788 (FortiClientEMS SQL injection) ... | Akira is a ransomware-as-a-service (RaaS) group that emerged in March 2023... Akira initially coded its ransomware in C++ for Windows... but introduced a new Rust-based variant in August 2023 (dubbed 'Megazord')... The group currently operates four primary variants: Akira, Megazord, Akira Linux, and Akira_v2.
and CVE-2020-3259, a memory disclosure vulnerability which can be used to retrieve credentials without authentication. | Unmasking Akira: the ransomware tactics you can’t afford to ignore... Akira focuses on being a double extortion group... first stealing data, then encrypting it, demanding payment to prevent public leaks and restore systems.
Akira have been observed to exploit Veeam vulnerabilities such as CVE-2023-27532 and CVE-2024-40711. | Unmasking Akira: the ransomware tactics you can’t afford to ignore... Akira focuses on being a double extortion group... first stealing data, then encrypting it, demanding payment to prevent public leaks and restore systems.
Akira have been observed to exploit Veeam vulnerabilities such as CVE-2023-27532 and CVE-2024-40711. | Unmasking Akira: the ransomware tactics you can’t afford to ignore... Akira focuses on being a double extortion group... first stealing data, then encrypting it, demanding payment to prevent public leaks and restore systems.
Additional exploited vulnerabilities include ... CVE-2024-37085 (VMware ESXi authentication bypass) ... | Akira is a ransomware-as-a-service (RaaS) group that emerged in March 2023... Akira initially coded its ransomware in C++ for Windows... but introduced a new Rust-based variant in August 2023 (dubbed 'Megazord')... The group currently operates four primary variants: Akira, Megazord, Akira Linux, and Akira_v2.
ReliaQuest identified what we assess with medium confidence to be the first known exploitation of this vulnerability, spanning multiple environments between February and March 2026... CVE-2024-12802 is an authentication bypass vulnerability in SonicWall appliances that reduces VPN security to single-factor authentication... On Gen6 devices, the firmware patch alone doesn’t remediate the vulnerability. Six additional manual reconfiguration steps are required.
In Q4 2023, Kroll identified an uptick in engagements involving Akira ransomware, a trend that has continued into 2024... Shortly after privilege escalation, Akira ransomware was deployed to encrypt systems.
CVE-2023-48365: Qlik Sense Enterprise HTTP Tunneling RCE (CVSS 9.9)
CVE-2025-23006: SonicWall SMA 1000 Pre-Auth Deserialization RCE (CVSS 9.8)
CVE-2024-21762: Fortinet FortiOS SSL VPN Out-of-Bounds Write RCE (CVSS 9.8)
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Figure 3 below represents the total number of victims claimed by The Gentlemen in 2025 compared to both Qilin and Akira, tracked by Unit 42 as Howling Scorpius.
The crown jewel of their operations is the use of the ransomware that gives them their name: Akira ... It retains various capabilities such as controlling disk drives, managing running processes, multi-threaded operation, and, of course, encrypting files and writing ransom notes on the victim’s devices.
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
In July 2024, Microsoft also linked the Storm-1175 threat group, along with three other cybercrime gangs, to Black Basta and Akira ransomware attacks that exploited a VMware ESXi authentication-bypass flaw.
"...the use of this technique has led to Akira and Black Basta ransomware deployments."
"...the use of this technique has led to Akira and Black Basta ransomware deployments."
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Den Berichten zufolge sei es Angreifern gelungen, Zugangsdaten zu entwenden, administrativen Zugriff durch über-privilegierte Konten zu erhalten ...
Den Berichten zufolge sei es Angreifern gelungen, Zugangsdaten zu entwenden, administrativen Zugriff durch über-privilegierte Konten zu erhalten ...
... und sich persistenten Zugriff durch neue Nutzer, etablierten SSH Zugriff und weitere Tools zu verschaffen.
Ebenso wurde von den Angreifern versucht, eine mögliche Detektion zu vermeiden, indem Sicherheitsfeatures deaktiviert wurden.
290 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware cited as an example of AI-driven ransomware targeting critical sectors in Africa.
Ransomware family mentioned in passing as responsible for a separate breach involving Ruag's U.S. subsidiary, with data theft and ransom payment.
Conventional cyber extortion/ransomware group mentioned as holding market share in Q2 2026 and relying on more traditional scalable entry vectors.
Ransomware family mentioned as having used SonicWall-related exploited defects in prior campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.