Akira ransomware-as-a-service affiliates breached organizations through compromised Atera RMM/MSP credentials, stolen RDP credentials, and a compromised SSL-VPN service account in three intrusions observed in a shared managed environment. Despite differing entry points, the actors performed reconnaissance, activated accounts, and stole credentials; two used Impacket WmiExec and esentutl to obtain Chrome credentials. Their outcomes diverged: one targeted ESXi with a Linux encryptor, one exfiltrated data without observed encryption, and another shut down Hyper-V virtual machines before deploying a renamed Akira encryptor.
The affiliates used varied data-theft paths, including Rclone with Wasabi, WinSCP/SFTP, and—in one case—no observed exfiltration before encryption. Defenders should prioritize detection of suspicious RMM-launched child processes, Cloudflare Tunnel activity, Veeam database credential queries, Impacket output redirection, browser-database copying, archive staging, and SafeBoot, ESXi, or Hyper-V actions preceding encryption. Akira has historically relied heavily on compromised VPN credentials where MFA was absent and uses double extortion; reporting has also linked some Akira ransom-payment flows and technical traits to Conti-affiliated actors.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
The FBI and CISA updated their #StopRansomware advisory AA24-109A on Akira ransomware, following the agencies' original April 2024 advisory.
Avast released a decryptor for Akira ransomware. Akira actors subsequently modified their encryption routine, potentially limiting the decryptor's usefulness for files encrypted later.
Akira ransomware was first observed as a ransomware-as-a-service operation. It typically exfiltrates data before encrypting systems to support double-extortion demands.
In a third intrusion, an affiliate used a compromised third-party monitoring-agent service account to access an SSL-VPN, reset the account password, performed discovery, and stole browser credentials and sensitive employee documents. The actor shut down Hyper-V virtual machines and executed a renamed Akira encryptor, creating an Akira ransom note after encryption began.
In a second intrusion, an affiliate accessed the environment through external RDP using a compromised domain-administrator account. The actor activated local Administrator accounts, harvested Chrome credentials, staged password-protected archives, and exfiltrated data through WinSCP to external SFTP servers; no ransomware deployment was observed.
In one intrusion, an Akira affiliate used compromised managed-service-provider credentials to access an Atera RMM portal and execute commands on managed endpoints. The actor installed Cloudflare Tunnel and AnyDesk, obtained Veeam database credentials, exfiltrated backup and QuickBooks data, and prepared an ESXi host for Linux ransomware deployment.
Arctic Wolf's blockchain analysis identified at least three transactions in which Akira actors sent full ransom payments totaling more than $600,000 to Conti-affiliated addresses. The firm assessed with high confidence that some Conti-affiliated actors were linked to Akira.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
shroudcloud.io
Open sourceshroudcloud.io
Open sourcehalcyon.ai
Open sourceblog.talosintelligence.com
Open sourcearcticwolf.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.