Akira, a financially motivated ransomware operation active since early 2023, steals sensitive data before encrypting systems and threatens publication to pressure victims into paying. Its targets span healthcare, education, finance, manufacturing, and government across North America, Europe, and Australia. Reported figures indicate more than 250 affected organizations and approximately $42 million in ransom proceeds as of January 1, 2024; a separate leak-site claim cited more than 350 compromises. ThreatMon reported that Akira targeted Ecuador’s Xtrim TVCable in November 2024 and leaked financial records and customer data after ransom negotiations failed.
Akira commonly gains access through compromised VPN credentials, absent multifactor authentication, and vulnerabilities in Cisco ASA and Firepower Threat Defense software; reported techniques also include phishing and exploitation of weak credentials. Attackers then use readily available tools for credential theft, network discovery, and data exfiltration. Payloads include the original C++ ransomware, Rust-based Megazord, and Akira_v2, targeting Windows and VMware ESXi systems. Darkatlas associates the operation with PUNK SPIDER and GOLD SAHARA, although its ransomware-as-a-service status remains disputed. Priority defenses include enforcing multifactor authentication, patching and restricting VPN access, strengthening endpoint monitoring and access controls, and maintaining tested offline backups.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
Akira reportedly targeted Ecuadorian telecommunications provider Xtrim TVCable in November 2024.
Akira was observed targeting an unnamed Latin American aerospace entity in June 2024. The reference does not specify the attack's outcome or whether data was encrypted or leaked.
Some Akira attacks began deploying Megazord, a Rust-based ransomware variant that appends the .powerranges extension. Operators continued using Megazord and other Akira variants interchangeably.
The first named leak-site victim associated with GOLD SAHARA appeared. The report identifies GOLD SAHARA as a cybercrime group deploying Akira ransomware.
PUNK SPIDER was first identified as a big-game-hunting adversary. The report describes it as developing and maintaining Akira ransomware and its dedicated leak site.
Akira operators introduced a Linux ransomware variant targeting VMware ESXi virtual machines, expanding beyond their initial focus on Windows systems.
Akira operations were first identified in March 2023. The financially motivated operation used double extortion, stealing victim data before encryption and threatening to publish it.
Third-party investigators observed Windows-specific Megazord ransomware and the Akira_v2 ESXi encryptor deployed concurrently during the same compromise.
On November 13–14 of an unspecified year, Akira published 35 leak-site posts: 32 newly named victims and three previously announced victims moved from News to Leaks. Twenty-five posts concerned organizations in the United States.
Following failed ransom negotiations, Akira reportedly leaked Xtrim TVCable's sensitive information, including financial records and customer data.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 39 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
blog.polyswarm.io
Open sourcedarkatlas.io
Open sourcethreatmon.io
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.