Megazord is a ransomware encryptor associated with Akira ransomware operations. Multiple sources in the provided content state that beginning in August 2023, some Akira intrusions deployed Megazord alongside Akira and Akira_v2, and that the operators used these variants interchangeably. Megazord is described as a Rust-based encryptor used against Windows hosts; when it encrypts files, it appends the .powerranges extension. Sophos reported observing only a single Megazord case in late August 2023, while joint government and industry reporting indicates the variant was used in a subset of Akira attacks from August 2023 and likely fell out of use after 2024 as tooling consolidated. Because Megazord is tied to Akira activity, the surrounding intrusion tradecraft reported with those operations includes initial access via VPN services lacking MFA, exploitation of Cisco vulnerabilities including CVE-2020-3259 and CVE-2023-20269, exposed RDP, spear phishing, and valid-account abuse; post-compromise behaviors included credential theft with tools such as Mimikatz and LaZagne, reconnaissance with SoftPerfect and Advanced IP Scanner, disabling security tools including abuse of PowerTool against the Zemana AntiMalware driver, data exfiltration with FileZilla, WinRAR, WinSCP, and RClone, and use of remote access/tunneling tools such as AnyDesk, RustDesk, Ngrok, and Cloudflare Tunnel. Detection content referenced in the sources includes YARA rules added for Megazord ransomware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Akira predominantly gains access through compromised VPN credentials lacking multi-factor authentication... Secondary access methods include ... purchasing access from initial access brokers.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Megazord is a ransomware family identified by unique YARA signatures. It is related to the win.akira family detection.
Ransomware encryptor/tooling observed deployed alongside Akira_v2 (noted as previously used targeting Windows environments), and assessed in the content as potentially fading out as Akira consolidates tooling.
A Rust-based ransomware variant used in Akira attacks from August 2023 onward, encrypting files with a .powerranges extension and used interchangeably with Akira in some operations.
Ransomware encrypting Windows hosts and appending .powerranges extension.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.