HackerFeeds
All ransomware groups

akira

1,613 tracked victims
·first seen 2023-04-12·last activity 2026-09-21

Group profile

The Akira ransomware group is said to have emerged in March 2023, and there's much speculation about its ties to the former CONTI ransomware group.<br> <br> It's worth noting that with the end of CONTI's operation, several affiliates migrated to independent campaigns such as Royal, BlackBasta, and others.<br> <br> According to some reports, Akira affiliates also work with other ransomware operations, such as Snatch and BlackByte, as an open directory of tools used by an Akira operator was identified, which also had connections to the Snatch ransomware.<br> <br> The first version of the Akira ransomware was written in C++ and appended files with the '.akira' extension, creating a ransom note named 'akira_readme.txt,' partially based on the Conti V2 source code. However, on June 29, 2023, a decryptor for this version was reportedly released by Avast.<br> <br> Subsequently, a version was released that fixed the decryption flaw on July 2, 2023. Since then, the new version is said to be written in Rust, this time called 'megazord.exe,' and it changes the extension to '.powerranges' for encrypted files.<br> <br> Most of Akira's initial access vectors use brute-force attempts on Cisco VPN devices (which use single-factor authentication only).<br> Additionally, exploitation of CVEs: CVE-2019-6693 and CVE-2022-40684 for initial access has been identified.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1078Valid Accounts

    Utilizes compromised VPN credentials.

  • T1078.002Valid Accounts: Domain Accounts

    Operators use obtained domain accounts for access.

  • T1133External Remote Services

    Actors exploit CVE-2023-20269 remote service vulnerabilities.

  • T1190Exploit Public-Facing Application

    Targets vulnerable CISCO devices via CVE-2023-20269.

TA0002

Execution

  • T1047Windows Management Instrumentation

    Actors may use WMI to continue the attack.

  • T1059Command and Scripting Interpreter

    Accepts parameters for its routines such as "-n 10" (for encryption percentage) or "-s (filename)" (for shared folder encryption).

  • T1059.001Command and Scripting Interpreter: PowerShell

    Operators use PowerShell to launch commands to continue operations.

  • T1059.002System Services: Service Execution

    Akira ransomware uses service execution for persistence.

  • T1059.003Command and Scripting Interpreter: Windows Command Shell

    Operators use CMD to launch commands to continue operations.

TA0003

Persistence

  • T1136.001Create Account: Local Account

    Upon initial access, Akira operators create a local account on the compromised system.

  • T1136.002Create Account: Domain Account

    Upon initial access, Akira operators create a domain account on the compromised system.

TA0004

Privilege Escalation

  • T1078.002Valid Accounts: Domain Accounts

    Utilizes valid domain accounts for privilege escalation.

  • TA0004Privilege Escalation

    Utilizes local domain accounts for privilege escalation.

TA0005

Stealth

  • T1027.001Obfuscated Files or Information: Binary Padding

    [Akira](https://attack.mitre.org/groups/G1024) has used binary padding to obfuscate payloads.(Citation: Cisco Akira Ransomware OCT 2024)

  • T1036.005Masquerading: Match Legitimate Resource Name or Location

    [Akira](https://attack.mitre.org/groups/G1024) has used legitimate names and locations for files to evade defenses.(Citation: Cisco Akira Ransomware OCT 2024)

  • T1112Modify Registry

    Uses commands in its operation to modify registries.

  • T1562.001Impair Defenses: Disable or Modify Tools

    Usage of PowerTool or a KillAV tool abusing the Zemana AntiMalware driver to terminate AV-related processes was observed.

TA0006

Credential Access

  • T1003.001OS Credential Dumping: LSASS Memory

    Uses Mimikatz, LaZagne, or a command line to dump LSASS from memory.

  • T1558Steal or Forge Kerberos Tickets

    [Akira](https://attack.mitre.org/groups/G1024) have used scripts to dump Kerberos authentication credentials.(Citation: Cisco Akira Ransomware OCT 2024)

TA0007

Discovery

  • T1018Remote System Discovery

    Uses Advanced IP Scanner and MASSCAN to discover remote systems.

  • T1082System Information Discovery

    Uses PCHunter and SharpHound to collect system information.

  • T1482Domain Trust Discovery

    [Akira](https://attack.mitre.org/groups/G1024) uses the built-in [Nltest](https://attack.mitre.org/software/S0359) utility or tools such as [AdFind](https://attack.mitre.org/software/S0552) to enumerate Active Directory trusts in victim environments.(Citation: Arctic Wolf Akira 2023)

  • TA0007Discovery

    Uses AdFind, Windows net command, and nltest to collect domain information.

TA0008

Lateral Movement

  • T1021.001Remote Services: Remote Desktop Protocol

    Utilizes remote services for accessing accounts and machines through remote services.

  • T1570Lateral Tool Transfer

    Uses RDP to move laterally within the victim's network.

TA0009

Collection

  • T1213.002Data from Information Repositories: Sharepoint

    [Akira](https://attack.mitre.org/groups/G1024) has accessed and downloaded information stored in SharePoint instances as part of data gathering and exfiltration activity.(Citation: Secureworks GOLD SAHARA)

  • T1560.001Archive Collected Data: Archive via Utility

    Utilizes discovery to gather information for exfiltration.

TA0010

Exfiltration

  • T1048.003Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol

    Utilizes FileZilla or WinSCP to exfiltrate stolen information via FTP.

  • T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage

    Uses RClone to exfiltrate stolen information via a web service.

TA0011

Command and Control

  • T1219Remote Access Tools

    [Akira](https://attack.mitre.org/groups/G1024) uses legitimate utilities such as AnyDesk and PuTTy for maintaining remote access to victim environments.(Citation: Secureworks GOLD SAHARA)(Citation: Arctic Wolf Akira 2023)

  • T1229Remote Access Software

    Utilizes AnyDesk, Radmin, Cloudflare Tunnel, MobaXterm, RustDesk, or Ngrok to gain remote access on targeted systems.

TA0040

Impact

  • T1486Data Encrypted for Impact

    Akira ransomware is used to encrypt files.

  • T1490Inhibit System Recovery

    Deletes shadow copies to inhibit recovery.

  • T1531Account Access Removal

    [Akira](https://attack.mitre.org/groups/G1024) deletes administrator accounts in victim networks prior to encryption.(Citation: Secureworks GOLD SAHARA)

  • T1657Financial Theft

    [Akira](https://attack.mitre.org/groups/G1024) engages in double-extortion ransomware, exfiltrating files then encrypting them, in order to prompt victims to pay a ransom.(Citation: BushidoToken Akira 2023)(Citation: CISA Akira Ransomware APR 2024)

TA0112

Defense Impairment

  • T1685Disable or Modify Tools

    [Akira](https://attack.mitre.org/groups/G1024) has disabled or modified security tools for defense evasion.(Citation: Cisco Akira Ransomware OCT 2024)

Recent victims

showing 50 of 1,616
DateWebsite / victimSectorCountry
2026-09-22
C
Coe Press Equipment
ManufacturingUS
2026-09-22
T
TDMI
Not Found
2026-09-22
D
DI.C.S.EL. S.R.L.
ManufacturingIT
2026-09-21
prestigemgt.com
Prestige Managementprestigemgt.com
Professional ServicesUS
2026-09-18
anderson-industries.com
Anderson Industriesanderson-industries.com
ManufacturingUS
2026-08-20
maximizedrevenue.com
Practice Management (maximizedrevenue.com)maximizedrevenue.com
Professional ServicesUS
2026-09-17TechnologyBR
2026-09-07
javepchevrolet.com.br
Javep Chevroletjavepchevrolet.com.br
Retail & E-CommerceBR
2026-09-16
B
Blossomland Accounting
Professional Services
2026-09-16
B
Bee Maid Honey
Agriculture and Food ProductionCA
2026-09-16
M
Manders
ManufacturingGB
2026-09-15
P
Pilot Precision
Manufacturing
2026-06-23
lazyboyz.no
Lazyboyzlazyboyz.no
Other
2026-09-15
S
Southern California Telephone Company
Energy & UtilitiesUS
2026-08-19
akstamping.com
AK Stampingakstamping.com
Manufacturing
2026-09-10
E
Eagle Construction
Manufacturing
2026-08-26
georgecameronnash.com
George Cameron Nashgeorgecameronnash.com
Not Found
2026-09-09
K
Kyodo USA
ManufacturingUS
2026-09-08
B
Brent Electric
Energy & UtilitiesGB
2026-09-08
B
Brentwood Country Club
HospitalityUS
2026-09-08
C
CreateASoft
Technology
2026-09-04
S
Stransky Heiz-Mess-Regeltechnik GmbH
ManufacturingDE
2026-08-21Not Found
2026-08-11ManufacturingUS
2026-09-02
S
ScrubaDub Auto Wash Centers
Retail & E-CommerceUS
2026-08-14
algragroup.ch
Algra Groupalgragroup.ch
OtherCH
2026-09-01
C
Congressional Iron Works
Manufacturing
2026-09-01
F
Flex1
Not Found
2026-07-24
bykconstruction.com
BYK Constructionbykconstruction.com
ManufacturingUS
2026-08-31
kfzjost.de
KFZ-MEISTERBETRIEB JOST GmbHkfzjost.de
TransportationDE
2026-08-07
galecu.net
Gale Credit Uniongalecu.net
Financial ServicesUS
2026-08-31
W
WEMS
Other
2026-08-28
A
Alumax
ManufacturingUS
2026-08-28
B
BEPeterson
Not Found
2026-08-28
J
JRT Mechanical
Manufacturing
2026-08-06ManufacturingUS
2026-08-27Other
2026-07-31
seabrookisland.com
Seabrook Islandseabrookisland.com
HospitalityUS
2026-08-14
gillrockdrill.com
Gill Rock Drillgillrockdrill.com
Manufacturing
2026-08-26
O
Oral and Maxillofacial Surgery
Healthcare
2026-08-26
P
PA-ID
Not Found
2026-08-11
winter-ingenieure.de
WINTER Ingenieurewinter-ingenieure.de
ManufacturingDE
2025-10-08
davisferber.com
Davis & Ferberdavisferber.com
Professional Services
2026-08-24
B
Bihl
OtherDE
2026-07-10Retail & E-CommerceUS
2026-07-30
cascadecoffee.com
Cascade Coffeecascadecoffee.com
Retail & E-CommerceUS
2026-08-20
D
Deas Millwork
Manufacturing
2026-08-19
ericksenkrentel.com
Ericksen Krentelericksenkrentel.com
Professional Services
2026-08-18
B
Borchert & LaSpina
Not Found
2026-07-29TechnologyUS