Akira is a ransomware operation active since March 2023 that conducts double-extortion attacks against corporate networks. Affiliates have gained access through compromised VPN credentials, exposed remote-access services, exploitation of known vulnerabilities in perimeter appliances, and credential attacks. Observed intrusions include discovery and Active Directory enumeration, creation of local and domain accounts, use of legitimate remote-management tools, lateral movement over RDP and SMB administrative shares, and theft of corporate data before encryption. Akira operators have targeted backup infrastructure and recovery mechanisms, including Veeam environments and Volume Shadow Copies, and have attempted to disable endpoint security controls; one observed affiliate used Safe Mode with Networking to impair EDR protections. The ransomware encrypts a broad range of business, database, virtual-machine, disk-image, and backup-related data while avoiding selected operating-system and executable files. It can use the Windows Restart Manager API to stop processes and services that obstruct encryption. Akira uses a leak site and Tor-based negotiation portal to pressure victims with threatened publication or sale of stolen data. Victims span numerous sectors, including construction, manufacturing, education, finance, real estate, consulting, technology, healthcare, and professional services, with substantial activity reported against organizations in the United States and North America.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
SonicWall has determined that recent SSLVPN security incidents affecting Gen 7 and newer firewalls are linked to CVE-2024-40766, not a zero-day vulnerability. | A potential undisclosed zero-day vulnerability in SonicWall Gen 7 firewall appliances is believed to be exploited by threat actors, leading to the deployment of Akira ransomware.
During the first half of 2023... Akira affiliates get into the network by leveraging stolen passwords or by exploiting CVE-2023-20269 (Cisco ASA and FTD) vulnerability, allowing them to conduct brute-force attack on local password without being detected... In two cases, attackers exploited CVE-2023-20269 vulnerability on a Cisco ASA VPN appliance. This vulnerability allows an unauthenticated attacker to conduct a brute-force attack on any local account while bypassing the maximum number of attempts defined. | During the first half of 2023, CERT Intrinsec handled several incidents involving Akira ransomware group... Akira ransomware is said to have started operating in March 2023 and targeted more than 140 organisations.
The first of these tools was named decrypt.py ... and is used for decrypting password data from Fortinet devices vulnerable to CVE-2019-6693... Unlike decrypt.py, this tool chains CVE-2019-6693 and CVE-2022-40684 in order to increase the effectiveness of exploitation. | Stairwell researchers recovered a home directory that had been accidentally publicly exposed from a server conducting exploitation of Fortinet appliances and deploying the Akira ransomware.
The other tool identified for exploitation of Fortinet devices was named fortiConfParser.py ... This Python script is used for remotely extracting the configuration of Fortinet devices, using a publicly known authentication bypass (CVE-2022-40684) ... Unlike decrypt.py, this tool chains CVE-2019-6693 and CVE-2022-40684 in order to increase the effectiveness of exploitation. | Stairwell researchers recovered a home directory that had been accidentally publicly exposed from a server conducting exploitation of Fortinet appliances and deploying the Akira ransomware.
Once connected via the VPN, the threat actor leveraged a remote code execution (RCE) vulnerability (CVE-2021-21972) in the VMware vCenter server. This vulnerability affects the ‘uploadOVA’ function, allowing unauthenticated attackers to upload malicious files to the vulnerable ‘/ui/vropspluginui/rest/services/*’ endpoint. | In this special Cyber Intelligence Briefing, our cyber experts at S-RM, Ineta Simkunaite and Callum Wilson, unravel a recent encounter with the Akira ransomware group. Their review unveils a novel privilege escalation technique used by attackers.
Additional exploited vulnerabilities include ... CVE-2023-48788 (FortiClientEMS SQL injection) ... | Akira is a ransomware-as-a-service (RaaS) group that emerged in March 2023... Akira initially coded its ransomware in C++ for Windows... but introduced a new Rust-based variant in August 2023 (dubbed 'Megazord')... The group currently operates four primary variants: Akira, Megazord, Akira Linux, and Akira_v2.
and CVE-2020-3259, a memory disclosure vulnerability which can be used to retrieve credentials without authentication. | Unmasking Akira: the ransomware tactics you can’t afford to ignore... Akira focuses on being a double extortion group... first stealing data, then encrypting it, demanding payment to prevent public leaks and restore systems.
Akira have been observed to exploit Veeam vulnerabilities such as CVE-2023-27532 and CVE-2024-40711. | Unmasking Akira: the ransomware tactics you can’t afford to ignore... Akira focuses on being a double extortion group... first stealing data, then encrypting it, demanding payment to prevent public leaks and restore systems.
Akira have been observed to exploit Veeam vulnerabilities such as CVE-2023-27532 and CVE-2024-40711. | Unmasking Akira: the ransomware tactics you can’t afford to ignore... Akira focuses on being a double extortion group... first stealing data, then encrypting it, demanding payment to prevent public leaks and restore systems.
Additional exploited vulnerabilities include ... CVE-2024-37085 (VMware ESXi authentication bypass) ... | Akira is a ransomware-as-a-service (RaaS) group that emerged in March 2023... Akira initially coded its ransomware in C++ for Windows... but introduced a new Rust-based variant in August 2023 (dubbed 'Megazord')... The group currently operates four primary variants: Akira, Megazord, Akira Linux, and Akira_v2.
ReliaQuest identified what we assess with medium confidence to be the first known exploitation of this vulnerability, spanning multiple environments between February and March 2026... CVE-2024-12802 is an authentication bypass vulnerability in SonicWall appliances that reduces VPN security to single-factor authentication... On Gen6 devices, the firmware patch alone doesn’t remediate the vulnerability. Six additional manual reconfiguration steps are required.
In Q4 2023, Kroll identified an uptick in engagements involving Akira ransomware, a trend that has continued into 2024... Shortly after privilege escalation, Akira ransomware was deployed to encrypt systems.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A potential undisclosed zero-day vulnerability in SonicWall Gen 7 firewall appliances is believed to be exploited by threat actors, leading to the deployment of Akira ransomware.
In this special Cyber Intelligence Briefing, our cyber experts at S-RM, Ineta Simkunaite and Callum Wilson, unravel a recent encounter with the Akira ransomware group. Their review unveils a novel privilege escalation technique used by attackers.
The crown jewel of their operations is the use of the ransomware that gives them their name: Akira ... It retains various capabilities such as controlling disk drives, managing running processes, multi-threaded operation, and, of course, encrypting files and writing ransom notes on the victim’s devices.
These RaaS programs include: Akira (Howling Scorpius) ALPHV (Ambitious Scorpius) DragonForce (Slippery Scorpius) Play (Fiddling Scorpius) Qilin (Spikey Scorpius) RansomHub (Spoiled Scorpius)
In July 2024, Microsoft also linked the Storm-1175 threat group, along with three other cybercrime gangs, to Black Basta and Akira ransomware attacks that exploited a VMware ESXi authentication-bypass flaw.
"...the use of this technique has led to Akira and Black Basta ransomware deployments."
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The attack chain demonstrates sophisticated TTPs including abuse of over-privileged LDAP/service accounts (notably 'sonicwall' and 'LDAPAdmin').
A suspected zero-day vulnerability affecting SonicWall Gen 7 firewall appliances ... with SSLVPN enabled. The exploit appears to bypass Time-based, One-Time Password (TOTP) Multi-Factor Authentication (MFA) implementations and provides threat actors with immediate network access.
The attack chain demonstrates sophisticated TTPs including abuse of over-privileged LDAP/service accounts (notably 'sonicwall' and 'LDAPAdmin').
Attackers consistently target Veeam Backup credential and exfiltrated Active Directory database NTDS.dit via wbadmin.exe.
The attack followed Akira’s standard playbook almost exactly: VPN credential spray resolved into a successful login at 03:52 UTC
dumped all Active Directory users and computers with a PowerShell enumeration that disabled truncation to capture every group membership
Paylogix determined that certain systems were subject to unauthorised access and certain files were copied from the Paylogix network between November 13, 2025 and November 18, 2025.
Threat actors gained access to its internal network and exfiltrated sensitive information; certain files were copied from the Paylogix network.
339 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware associated with the claimed compromise of BYK Construction and threatened publication of 27 GB of corporate and client data, including employee personal information, financial information, and project specifications.
Ransomware group that claimed responsibility for the Paylogix intrusion, asserted it had stolen confidential company data, and threatened public release unless ransom demands were paid.
Ransomware operation attributed in the report to the attack against Alumax; the actors claim they will publish 58 GB of allegedly exfiltrated corporate, employee, client, project, financial, and contractual data.
A ransomware-as-a-service brand whose reported operations use VPN and RDP access, valid accounts, exploitation of known CVEs, data exfiltration, recovery inhibition, and targeting of backup servers to increase extortion leverage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.