Researchers and incident responders reported that Akira ransomware affiliates used a repeatable intrusion playbook built around stolen VPN credentials and exploitation of internet-facing appliances, including Fortinet flaws CVE-2019-6693 and CVE-2022-40684 and Cisco ASA/FTD flaw CVE-2023-20269. Recovered attacker infrastructure exposed direct evidence of reconnaissance, credential theft, and exfiltration activity, including decrypted Fortinet configurations, password-protected RAR archives containing stolen victim data, and command history showing downloads from a public-facing victim server. Investigators said the operators relied heavily on legitimate administration tools such as AnyDesk, TeamViewer, OpenSSH, MobaXterm, PowerShell, WMI, Impacket, WinSCP, FileZilla, and Cloudflared, while moving laterally through RDP and SMB and attempting to disable defenses, erase evidence, and destroy Veeam backups before encryption.
Analysis of Akira’s malware and victim activity showed a double-extortion model that spans both Windows and Linux environments. The Linux variant supports selective path targeting, network-share encryption, partial encryption, file exclusions, and multithreaded execution using AES and RSA, dropping akira_readme.txt ransom notes with Tor-based contact details. Reporting also tied Akira to broad U.S.-focused targeting across sectors and suggested some operators may overlap with other ransomware-as-a-service programs, including possible links to Snatch. The group’s activity continued to affect organizations such as Texas-based CF Supply, where attackers were reported to have compromised corporate data that could include client project records, personal information, contracts, and agreements.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
The Akira-attributed breach affecting CF Supply was discovered on 2026-08-13 at 13:24 UTC, according to the source report.
CF Supply, a Texas-based construction products company, was listed as the victim of an Akira-attributed ransomware and data breach incident. The source listed the breach date as 2026-08-13 and said attackers planned to upload corporate data that could include project information, personal information, contracts, and agreements.
On 2023-07-21, CERT-In issued an alert stating that Akira ransomware leveraged publicly known VPN appliance vulnerabilities for initial access.
In late June 2023, Stairwell recovered a publicly exposed 99 GB home directory from a server used to exploit Fortinet appliances and support attacks associated with Akira ransomware. The dataset provided direct visibility into attacker tooling, reconnaissance, and exfiltration activity.
One consulting company whose IP address later appeared among Stairwell's observed targets had reportedly been attacked by the Snatch ransomware group in early June 2023.
CERT Intrinsec reported that the Akira ransomware group began operating in March 2023.
CERT Intrinsec analyzed several Akira ransomware incidents from the first half of 2023 and documented a recurring three-phase intrusion pattern involving initial access, stealthy data assessment and exfiltration, and final encryption.
A later malware analysis documented a Linux-targeting Akira ransomware variant, describing its execution parameters, ransom note behavior, encryption design, and support for encrypting network shares.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
hookphish.com
Open sourcestairwell.com
Open sourcemalwareanalysisspace.blogspot.com
Open sourceintrinsec.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.