Akira is a ransomware family and ransomware-as-a-service operation that emerged in 2023 and became a prominent financially motivated threat through double-extortion attacks. The operators steal data prior to encryption and use the threat of public disclosure alongside system recovery demands to pressure victims. Akira has targeted organizations across multiple sectors, with repeated reporting highlighting manufacturing, construction, professional services, healthcare, finance, education, and technology, and a strong concentration of victims in North America.
Akira initially deployed a Windows encryptor written in C++, then expanded with additional variants including a Rust-based variant commonly referred to as Megazord, a Linux/ESXi encryptor, and later variants used against broader virtualized environments. Reported behavior includes host and drive enumeration, process discovery and termination, multithreaded file encryption, ransom note creation, and deletion of shadow copies and backup artifacts to inhibit recovery. Akira operators are also known to target backup infrastructure and to terminate database, backup, and security-related services before encryption.
Intrusions attributed to Akira commonly begin through compromised VPN credentials, especially where MFA is absent, exploitation of edge-device and VPN vulnerabilities, spearphishing, brute-force activity against remote access services, and access obtained from initial access brokers. Post-compromise tradecraft includes persistence through creation of privileged accounts and deployment of remote access tools, reconnaissance with network scanners and Active Directory discovery utilities, credential theft from LSASS, Active Directory databases, browsers, and backup systems, lateral movement via RDP, SMB admin shares, SSH, PsExec, WMI, and related tooling, and exfiltration using common archive and file-transfer utilities. Multiple reports also describe defense evasion through disabling endpoint protections, clearing logs, using tunneling services, and in some cases bring-your-own-vulnerable-driver techniques.
Akira has been linked by multiple researchers to former Conti ecosystem personnel or tradecraft overlap, though the precise organizational relationship remains an assessment rather than a universally confirmed fact. Security vendors also track the threat under aliases including Howling Scorpius, Storm-1567, PUNK SPIDER, and GOLD SAHARA. The group has maintained a high operational tempo and is widely regarded as one of the more significant enterprise ransomware threats of the mid-2020s.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Additional exploited vulnerabilities include ... CVE-2023-48788 (FortiClientEMS SQL injection) ... | Akira is a ransomware-as-a-service (RaaS) group that emerged in March 2023... Akira initially coded its ransomware in C++ for Windows... but introduced a new Rust-based variant in August 2023 (dubbed 'Megazord')... The group currently operates four primary variants: Akira, Megazord, Akira Linux, and Akira_v2.
and CVE-2020-3259, a memory disclosure vulnerability which can be used to retrieve credentials without authentication. | Unmasking Akira: the ransomware tactics you can’t afford to ignore... Akira focuses on being a double extortion group... first stealing data, then encrypting it, demanding payment to prevent public leaks and restore systems.
Additional exploited vulnerabilities include CVE-2023-20269 (Cisco ASA/FTD zero-day) ... MITRE ATT&CK TTP Matrix ... CVE-2023-20269 (Cisco) | Akira is a ransomware-as-a-service (RaaS) group that emerged in March 2023... Akira initially coded its ransomware in C++ for Windows... but introduced a new Rust-based variant in August 2023 (dubbed 'Megazord')... The group currently operates four primary variants: Akira, Megazord, Akira Linux, and Akira_v2.
Akira have been observed to exploit Veeam vulnerabilities such as CVE-2023-27532 and CVE-2024-40711. | Unmasking Akira: the ransomware tactics you can’t afford to ignore... Akira focuses on being a double extortion group... first stealing data, then encrypting it, demanding payment to prevent public leaks and restore systems.
Akira have been observed to exploit Veeam vulnerabilities such as CVE-2023-27532 and CVE-2024-40711. | Unmasking Akira: the ransomware tactics you can’t afford to ignore... Akira focuses on being a double extortion group... first stealing data, then encrypting it, demanding payment to prevent public leaks and restore systems.
From late 2024 to the present day, the most common initial access method by Akira is the abuse of SonicWall SSLVPNs... The use of CVE-2024-40766 is a high contributing factor. | Unmasking Akira: the ransomware tactics you can’t afford to ignore... Akira focuses on being a double extortion group... first stealing data, then encrypting it, demanding payment to prevent public leaks and restore systems.
Additional exploited vulnerabilities include ... CVE-2024-37085 (VMware ESXi authentication bypass) ... | Akira is a ransomware-as-a-service (RaaS) group that emerged in March 2023... Akira initially coded its ransomware in C++ for Windows... but introduced a new Rust-based variant in August 2023 (dubbed 'Megazord')... The group currently operates four primary variants: Akira, Megazord, Akira Linux, and Akira_v2.
ReliaQuest identified what we assess with medium confidence to be the first known exploitation of this vulnerability, spanning multiple environments between February and March 2026... CVE-2024-12802 is an authentication bypass vulnerability in SonicWall appliances that reduces VPN security to single-factor authentication... On Gen6 devices, the firmware patch alone doesn’t remediate the vulnerability. Six additional manual reconfiguration steps are required.
In Q4 2023, Kroll identified an uptick in engagements involving Akira ransomware, a trend that has continued into 2024... Shortly after privilege escalation, Akira ransomware was deployed to encrypt systems.
CVE-2023-48365: Qlik Sense Enterprise HTTP Tunneling RCE (CVSS 9.9)
CVE-2025-23006: SonicWall SMA 1000 Pre-Auth Deserialization RCE (CVSS 9.8)
CVE-2024-21762: Fortinet FortiOS SSL VPN Out-of-Bounds Write RCE (CVSS 9.8)
CVE-2023-27997: Fortinet FortiOS SSL VPN Heap Buffer Overflow RCE - XORtigate (CVSS 9.8)
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Figure 3 below represents the total number of victims claimed by The Gentlemen in 2025 compared to both Qilin and Akira, tracked by Unit 42 as Howling Scorpius.
The crown jewel of their operations is the use of the ransomware that gives them their name: Akira ... It retains various capabilities such as controlling disk drives, managing running processes, multi-threaded operation, and, of course, encrypting files and writing ransom notes on the victim’s devices.
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
In July 2024, Microsoft also linked the Storm-1175 threat group, along with three other cybercrime gangs, to Black Basta and Akira ransomware attacks that exploited a VMware ESXi authentication-bypass flaw.
"...the use of this technique has led to Akira and Black Basta ransomware deployments."
"...the use of this technique has led to Akira and Black Basta ransomware deployments."
4 distinct techniques documented for this family, organized by ATT&CK tactic.
287 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group mentioned in sector specialization discussion, particularly targeting manufacturing and construction.
Ransomware family mentioned as having used SonicWall defects in prior campaigns.
Akira4
A ransomware operation mentioned for comparison with The Gentlemen’s victim volume.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.