TLP:CLEAR
$ ECRIME · RANSOMWARE-AS-A-SERVICE · ASSESSED RUSSIA / POST-SOVIET (NO FORMAL STATE ATTRIBUTION)
// Threat Actor Profile — Ransomware-as-a-Service (RaaS) Operator

AKIRA

PROFILE COMPILED: 2026-09-03  |  SOURCES: CISA/FBI/DC3/HHS/Europol/OFAC-France/Germany/NCSC-NL Joint Advisory AA24-109A (orig. Apr 2024, updated Nov 2025), MITRE ATT&CK G1024, Arctic Wolf Labs, TRM Labs, Trend Micro, Unit 42 (Howling Scorpius), Rapid7, Sophos X-Ops, and 12+ additional vendor/OSINT sources
Status: ACTIVE
Threat Level: CRITICAL
Primary Motive: Financial — Double Extortion
Active Since: March 2023
MITRE ATT&CK: G1024
Law Enforcement Action: NONE CONFIRMED AS OF NOV 2025
$244M+
Ransom Proceeds Claimed (USD, as of Sep 2025)
1,584
Victims Posted to Leak Site (Cumulative, as of Aug 2026)
8
CVEs Actively Weaponized for Initial Access
~55 MIN
Fastest Observed Time-to-Encryption (SonicWall Campaign, Jul 2025)
00
Overview

Akira is a Ransomware-as-a-Service (RaaS) operation first observed in March 2023, notable both for its distinctive 1980s "green-screen" leak-site aesthetic and for becoming — in under three years — one of the most prolific ransomware operations currently tracked, with joint US/EU law enforcement reporting approximately $244.17 million in claimed ransom proceeds and a cumulative leak-site victim count that had reached 1,584 organizations by late August 2026 (CISA/FBI/Europol Joint Advisory AA24-109A, updated Nov 13, 2025; leak-site tracking via TRM Labs and Comparitech). It matters right now because Akira has filled market share left vacant by law-enforcement disruptions of peer operations (LockBit, BlackCat/ALPHV, Hive) without suffering a comparable takedown itself, and because its operational tempo has been accelerating rather than plateauing — a July–August 2025 surge tied to a critical SonicWall SonicOS vulnerability (CVE-2024-40766, CVSS 9.3) saw encryption completed in as little as 55 minutes from initial access in some incidents (Arctic Wolf Labs, Aug 2025).

Technically, Akira sits at the intersection of two notable trends in contemporary ransomware operations: near-total reliance on living-off-the-land tooling (commercial remote-access software, open-source credential dumpers, and legitimate cloud-sync utilities rather than bespoke C2 infrastructure) and aggressive, opportunistic exploitation of internet-facing edge devices — VPN concentrators and backup appliances specifically — that lack phishing-resistant multifactor authentication. The joint advisory names eight distinct CVEs across Cisco ASA/FTD, SonicWall SonicOS, and Veeam Backup & Replication that Akira affiliates have weaponized for initial access, several of them years-old and already patched, underscoring that unpatched edge infrastructure — not novel zero-day tradecraft — remains the group's primary way in.

Akira is widely assessed, with a meaningful evidentiary basis rather than mere reputation, to include personnel from the dissolved Conti syndicate: beyond well-documented code and behavioral overlap (itself weak evidence on its own, since Conti's source code leaked publicly in March 2022), Arctic Wolf Labs traced three separate Bitcoin transactions totaling over $600,000 from Akira-controlled ransom wallets directly to addresses previously associated with Conti leadership. This places Akira within a broader "Conti diaspora" ecosystem that also appears to include the Fog and Frag ransomware operations, which share infrastructure and on-chain financial patterns with Akira and with each other.

Where this profile's compiling organization's operational context is concerned, Akira's sector targeting is broad but shows a documented preference for educational institutions alongside critical manufacturing, healthcare, IT, financial services, and food and agriculture — the group is opportunistic and CVE-driven rather than a strategic, hand-picked-target operation, meaning any organization running unpatched or MFA-less edge infrastructure in these sectors sits within its realistic targeting envelope regardless of size, though CISA notes a continuing preference for small- and medium-sized businesses even as larger organizations and critical infrastructure entities are increasingly affected.

01
Identity & Attribution
Primary NameAkira
Sponsor / ParentNone — independent eCrime RaaS collective; assessed Conti-diaspora lineage (see Analyst Assessment)
Actor TypeeCrime — Ransomware-as-a-Service (RaaS) operator
Primary MotivationFinancial (double-extortion ransom)
Active SinceMarch 2023
Last ObservedOngoing — sustained leak-site activity through Aug 2026
MITRE G-IDG1024
Legal StatusNo indictment, arrest, or OFAC sanction specific to Akira as of the Nov 2025 advisory — unlike several individually-sanctioned Conti/TrickBot members (Feb & Sep 2023)
Tracking Aliases
AKIRA STORM-1567 (Microsoft) HOWLING SCORPIUS (Palo Alto Unit 42) PUNK SPIDER GOLD SAHARA (Secureworks)
Attribution Confidence

[HIGH] confidence that Akira, as a leak-site brand and RaaS toolset, is the entity described consistently across CISA/FBI/Europol reporting and independent vendor tracking (convergent naming: Storm-1567, Howling Scorpius, Gold Sahara, Punk Spider all resolve to the same observed infrastructure and TTPs). [MEDIUM] confidence on Conti-personnel continuity — supported by direct blockchain evidence (three Bitcoin transactions, >$600K, traced from Akira wallets to known Conti leadership addresses per Arctic Wolf Labs), but code/behavioral overlap alone is discounted as weak evidence since Conti's source leaked publicly in March 2022 and is available to any operator. No confidence rating asserted on precise organizational structure, membership count, or leadership identity — these are not resolved in current public reporting, and no government indictment exists to formally anchor them.

02
Campaign & Operational Timeline
MAR 2023 – AUG 2023
Emergence & Windows-Only Phase
First observed March 2023 as a C++ Windows encryptor appending the .akira extension, launched alongside a distinctive 1980s "green-screen" Tor leak site. By late 2023, independent trackers documented at least 63 confirmed victims (Bushidotoken, TRM Labs).
APR 2023 – EARLY 2024
ESXi/Linux Pivot & First Federal Advisory
A Linux variant targeting VMware ESXi hypervisors was deployed starting April 2023; the group's encryptor shifted from C++ to a Rust-based tool ("Megazord") by August 2023. By January 1, 2024, joint FBI/CISA reporting counted over 250 impacted organizations and approximately $42 million in claimed ransom proceeds, prompting the original CISA/FBI/MS-ISAC/Europol advisory AA24-109A, published April 18, 2024.
2024 – MID-2025
Edge-Device Exploitation Escalation
Sustained weaponization of Cisco ASA/FTD flaws (zero-day CVE-2023-20269 and the older CVE-2020-3259, both added to CISA's KEV catalog specifically due to Akira exploitation) and Veeam Backup & Replication vulnerabilities (CVE-2023-27532, CVE-2024-40711). CISA's Aug 2025 threat brief and Rapid7/Darktrace reporting documented a sharp escalation once CVE-2024-40766 (SonicWall SonicOS improper access control, CVSS 9.3, disclosed Aug 23, 2024) entered wide exploitation — Akira accounted for roughly 40 ransomware incidents in July 2025 alone, the third-most-active group that month behind Qilin and INC Ransom, with encryption completed in as little as 55 minutes from initial SonicWall SSL VPN login (Arctic Wolf Labs).
JUN 2025 – NOV 2025
Hypervisor Expansion & Advisory Update
Trusted third-party reporting documented the first observed Akira encryption of Nutanix Acropolis Hypervisor (AHV) virtual machine disk files in a June 2025 incident — extending targeting beyond the historical VMware ESXi/Hyper-V focus. On November 13, 2025, FBI, CISA, DC3, HHS, Europol EC3, France's OFAC, Germany's Baden-Württemberg cybercrime authorities, and the Netherlands' NCSC-NL jointly reissued AA24-109A with updated TTPs documenting the Rust-based Akira_v2 ESXi/Linux encryptor, POORTRY/STONESTOP BYOVD tooling, and the $244.17 million cumulative ransom-proceeds figure.
2025 – 2026
Sustained High-Tempo Operations
The group posted approximately 980 new victims to its leak site between January 1 and December 11, 2025 alone. By August 31, 2026, cumulative publicly claimed victims reached 1,584 — making Akira, on leak-site volume, one of the most active ransomware brands currently tracked, with no law-enforcement disruption, seizure, or public indictment yet recorded against the operation as a whole (independent decryption research, not law enforcement action, has produced the only public recovery tooling — see Section 06).
03
Attack Lifecycle Edge-device exploitation → living-off-the-land intrusion → hybrid double-extortion

Entry vectors center overwhelmingly on internet-facing VPN and backup appliances lacking phishing-resistant MFA. CISA's advisory names eight specific CVEs Akira affiliates have weaponized — CVE-2020-3259 and CVE-2023-20269 (Cisco ASA/FTD), CVE-2020-3580, CVE-2023-28252, and CVE-2024-37085 (added in the Nov 2025 update), CVE-2023-27532 and CVE-2024-40711 (Veeam Backup & Replication), and CVE-2024-40766 (SonicWall SonicOS, CVSS 9.3, the current primary vector) — alongside straightforward credential theft, password spraying via the tool SharpDomainSpray, spearphishing, and abuse of exposed SSH on routers as a tunneling foothold into internal networks (CISA AA24-109A).

Toolchain is overwhelmingly living-off-the-land: AdFind, SoftPerfect NetScan, Advanced IP Scanner, and PCHunter64 for reconnaissance; nltest /dclist and nltest /DOMAIN_TRUSTS for domain-trust mapping; Mimikatz and LaZagne for credential dumping, with Kerberoasting used to extract credentials from LSASS process memory; and Impacket's wmiexec.py for remote command execution via WMI rather than disk-resident payloads. Defense evasion layers two distinct driver-abuse techniques: PowerTool exploiting the legitimate, signed Zemana AntiMalware driver to terminate AV processes, and the POORTRY/STONESTOP pairing — POORTRY is malware written as a signed vulnerable Windows driver, loaded via the STONESTOP installer, giving Akira operators kernel-level (Ring 0) EDR/AV termination through a genuine Bring-Your-Own-Vulnerable-Driver (BYOVD) technique.

C2 methodology relies almost entirely on legitimate third-party infrastructure rather than actor-registered domains or IPs: Ngrok and Cloudflare Tunnel (cloudflared) establish encrypted, outbound-only tunnels that bypass perimeter monitoring without requiring inbound firewall exceptions, while AnyDesk, LogMeIn, RustDesk, and MobaXterm provide remote-access channels deliberately chosen to blend with legitimate administrator activity rather than trigger malware-signature detection.

Lateral movement and persistence combine RDP, SSH, and WMIC with creation of a new domain administrative account — CISA's investigations repeatedly identified an account named itadm — and, in at least one documented intrusion, a distinctive privilege-escalation technique: temporarily powering down a domain controller's virtual machine, copying its VMDK disk file offline, attaching it to a newly created VM, and extracting the NTDS.dit database and SYSTEM registry hive from the dismounted disk to bypass live-host credential protections entirely.

Exfiltration and impact follow a double-extortion model: FileZilla and WinRAR (with 7-zip added per the Nov 2025 update) collect and compress data, which WinSCP and RClone then exfiltrate via FTP/SFTP or sync directly to MEGA cloud storage — in some 2025 incidents completed in just over two hours from initial access. Encryption itself uses a hybrid ChaCha20 stream cipher with RSA public-key exchange, customizable to full or partial encryption by file type and size, with the Windows-focused Megazord and the newer Rust-based, Linux/ESXi/Nutanix-AHV-capable Akira_v2 at times deployed simultaneously against different system architectures within a single intrusion. The encryptor (w.exe/Win.exe) deletes Volume Shadow Copy Service backups via PowerShell before completing encryption, and drops a ransom note (fn.txt or akira_readme.txt) in the C: root and every user directory — notably, the note contains no ransom figure; the amount is disclosed only after the victim initiates contact through a dedicated Tor negotiation portal.

04
TTPs — MITRE ATT&CK Mapping Enterprise framework only — no ICS/ATLAS-relevant activity identified in current reporting
Initial Access
T1190
Exploit Public-Facing Application
[HIGH] Weaponizes 8 distinct CVEs across Cisco ASA/FTD, SonicWall SonicOS, and Veeam Backup & Replication; CVE-2024-40766 (CVSS 9.3) is the current primary vector.
Initial Access
T1133
External Remote Services
[HIGH] Primary foothold is VPN services (especially SonicWall) lacking phishing-resistant MFA; credentials stolen, brute-forced, or purchased from initial access brokers.
Credential Access
T1110.003
Password Spraying
[HIGH] SharpDomainSpray tool used against VPN endpoints and account discovery.
Execution
T1059.001
PowerShell
[HIGH] Used for VSS deletion, credential harvesting, and disabling services ahead of encryption.
Persistence
T1136.002
Create Account: Domain Account
[HIGH] Creates a domain administrator account — repeatedly observed named itadm — to establish a durable foothold.
Credential Access
T1003.001
OS Credential Dumping: LSASS Memory
[HIGH] Kerberoasting extracts credentials from LSASS process memory; Mimikatz and LaZagne used as dumping tools.
Privilege Escalation
T1003.002 / T1003.003
OS Credential Dumping: Security Account Manager / NTDS
[HIGH] Distinctive offline technique: powers down the domain controller VM, copies its VMDK, mounts it to a new VM, and extracts NTDS.dit + SYSTEM hive to bypass live-host protections.
Defense Evasion
T1562.001
Impair Defenses: Disable or Modify Tools
[HIGH] PowerTool exploits the legitimate, signed Zemana AntiMalware driver to terminate antivirus-related processes.
Defense Evasion
T1068
Exploitation for Privilege Escalation (BYOVD)
[HIGH] POORTRY (signed vulnerable Windows driver malware) loaded via STONESTOP for kernel-level (Ring 0) EDR/AV termination.
Defense Evasion
T1027
Obfuscated Files or Information
[MEDIUM] HeartCrypt packer-as-a-service applied to payloads to defeat static/behavioral detection.
Discovery
T1018 / T1482
Remote System Discovery / Domain Trust Discovery
[HIGH] AdFind, SoftPerfect NetScan, Advanced IP Scanner; nltest /dclist and /DOMAIN_TRUSTS added per Nov 2025 update.
Lateral Movement
T1021.001 / T1219
Remote Desktop Protocol / Remote Access Software
[HIGH] AnyDesk, LogMeIn, RustDesk, MobaXterm chosen to blend with legitimate administrator activity during lateral movement.
Command & Control
T1572
Protocol Tunneling
[HIGH] Ngrok and Cloudflare Tunnel (cloudflared) establish encrypted, outbound-only C2 channels bypassing perimeter monitoring.
Exfiltration
T1567.002
Exfiltration to Cloud Storage
[HIGH] RClone syncs stolen data to MEGA; WinSCP for SFTP transfer; FileZilla/WinRAR/7-zip for collection and staging compression.
Impact
T1486
Data Encrypted for Impact
[HIGH] Hybrid ChaCha20 + RSA scheme; full/partial encryption customizable by file type and size; dual Windows (Megazord) + Linux/ESXi/Nutanix (Akira_v2) payloads at times deployed simultaneously.
Impact
T1657
Financial Theft
[HIGH] Double-extortion: ransom figure withheld until victim initiates contact via a dedicated Tor negotiation portal; threatens data leak regardless of encryption recovery.
05
Targeting Profile
Sector Targeting
Education
PRIMARY
Critical Manufacturing
HIGH
Healthcare & Public Health
HIGH
Information Technology
MED
Financial Services
MED
Food & Agriculture
LOW
GeographiesNorth America (primary), Europe, Australia
Victim ProfilePrimarily small- and medium-sized businesses; larger enterprises and critical infrastructure entities increasingly affected
Preferred EntryInternet-facing VPN/edge appliances (SonicWall, Cisco ASA/FTD) and unpatched Veeam backup servers lacking phishing-resistant MFA
Target DoctrineOpportunistic, CVE- and exposure-driven mass exploitation rather than bespoke pre-operation target selection
06
Tools, Malware & Infrastructure
MEGAZORD ENCRYPTOR (WINDOWS) · RUST · CISA AA24-109A
Windows-targeting Rust-based ransomware encryptor introduced August 2023, replacing the original C++ locker. Per CISA's Nov 2025 update, trusted third-party investigation determined Megazord "has likely fallen out of use since 2024," with Akira_v2 now the primary payload even on some Windows-adjacent deployments.
AKIRA_V2 ENCRYPTOR (LINUX/ESXI/NUTANIX AHV) · RUST · CISA AA24-109A
Current-generation encryptor targeting Linux, VMware ESXi, and (per the June 2025 incident) Nutanix Acropolis Hypervisor. Embeds a Build ID as a runtime execution condition — refuses to run without a matching ID, functioning as an anti-analysis gate. Supports vmonly (target only VMs) and stopvm (halt running VMs before encryption) flags; appends .akira, .powerranges, .akiranew, or .aki extensions depending on build.
POORTRY / STONESTOP BYOVD DRIVER + LOADER · CISA AA24-109A
POORTRY is malware written as a signed, vulnerable Windows driver, giving Akira operators kernel-level (Ring 0) code execution to terminate EDR/AV processes via a genuine Bring-Your-Own-Vulnerable-Driver (BYOVD) technique; STONESTOP serves as its loader/installer. Notably, this driver pair has been independently associated with other ransomware ecosystems in prior reporting, suggesting shared tooling supply rather than Akira-exclusive development.
POWERTOOL AV/EDR KILLER · ABUSED LEGITIMATE DRIVER · CISA AA24-109A
Exploits the legitimate, signed Zemana AntiMalware driver — rather than a bespoke malicious one — to terminate antivirus-related processes ahead of encryption; a second, distinct driver-abuse technique alongside POORTRY/STONESTOP.
MIMIKATZ / LAZAGNE CREDENTIAL DUMPERS · OPEN SOURCE
Open-source credential-dumping utilities used for Kerberos ticket extraction (Mimikatz) and stored-password recovery across Windows, Linux, and macOS (LaZagne), typically following Kerberoasting against LSASS process memory.
IMPACKET (WMIEXEC.PY) PYTHON NETWORK PROTOCOL LIBRARY · OPEN SOURCE
wmiexec.py specifically used for remote command execution via Windows Management Instrumentation, avoiding disk-resident payloads and standard process-creation detection.
ANYDESK / LOGMEIN / RUSTDESK / MOBAXTERM LEGITIMATE RMM / REMOTE ACCESS · COTS
Commercial remote-access and support software repurposed for lateral movement and persistence, chosen specifically to blend with legitimate helpdesk/administrator activity rather than trigger malware-signature detection.
NGROK / CLOUDFLARE TUNNEL (CLOUDFLARED) TUNNELING / REVERSE PROXY UTILITIES · COTS
Establish encrypted, outbound-only reverse-proxy channels to attacker infrastructure, avoiding inbound firewall rule requirements and blending with legitimate developer/DevOps use of the same widely-adopted tools.
RCLONE / WINSCP / FILEZILLA / WINRAR / 7-ZIP DATA COLLECTION & EXFILTRATION TOOLCHAIN · OPEN SOURCE / COTS
RClone syncs staged archives to MEGA cloud storage; WinSCP performs SFTP transfer to actor-controlled accounts; FileZilla provides FTP-based exfiltration; WinRAR and (per the Nov 2025 update) 7-zip compress and split data into .RAR archives prior to transfer.
HEARTCRYPT PACKER-AS-A-SERVICE
Commercial crypter/obfuscation service applied to Akira payloads to defeat static signature and behavioral heuristic detection prior to delivery.
SYSTEMBC RAT / PROXY BOT · COTS
Dual-purpose remote access trojan and SOCKS5 proxy bot, used both for command-and-control and as a network pivot point — a long-running commodity tool shared across numerous ransomware ecosystems, not unique to Akira.
ADFIND / SOFTPERFECT NETSCAN / ADVANCED IP SCANNER / PCHUNTER64 RECON & DISCOVERY TOOLCHAIN · COTS / OPEN SOURCE
Command-line and GUI network/Active Directory enumeration tools for host and domain-trust discovery; nltest /dclist and /DOMAIN_TRUSTS added to the toolkit per the Nov 2025 advisory update.
Vulnerability Cross-Reference — Gap
CVE-2024-40766 (SonicWall, CVSS 9.3, the group's current primary vector) now has a companion vuln card — (see vuln card: SONICWALL-SONICOS-ACCESS-CONTROL). The remaining seven CVEs Akira has weaponized (CVE-2020-3259, CVE-2020-3580, CVE-2023-20269, CVE-2023-27532, CVE-2023-28252, CVE-2024-37085, CVE-2024-40711) still have no companion vuln card in this project's output/vulns/ library (Heartbleed, Spectre/Meltdown, PaperCut, PrintNightmare, Rockwell Logix Auth Bypass, and WatchGuard Firebox Auth Bypass cover unrelated flaws).
Incident Cross-Reference
No companion incident card on file — none of this project's existing incident cards (Sony BMG, Estonia 2007, Iceman Carding, Operation Aurora, Operation Ababil, JPMorgan Chase, Bangladesh Bank SWIFT, Maersk NotPetya, CYCLOPS BLINK, Morris Worm) attribute to Akira. Given Akira's diffuse, opportunistic mass-victim model (1,584+ organizations), no single incident is likely to warrant a dedicated incident card in the way a targeted nation-state operation would — this actor card is the appropriate primary record.
07
Indicators of Compromise All IPs and domains defanged
⚠ IOC HANDLING — No actor-registered IP or domain infrastructure was published in the referenced Nov 2025 CISA advisory; Akira's C2 relies almost entirely on legitimate third-party services (Ngrok, Cloudflare Tunnel, AnyDesk, MEGA) rather than actor-owned infrastructure, which is itself a notable OPSEC characteristic (see Section 10). All hashes below are reproduced verbatim from CISA/FBI Joint Advisory AA24-109A Table 2 (observation window: June 2023 – August 2025); vet against current threat-intel feeds before operational use. Reference URLs in Section 13 are NOT defanged.
Type Value / Description Source Date
HASH (SHA-256)d2fd0654710c27dcf37b6c1437880020824e161dd0bf28e3a133ed777242a0ca — w.exe, Akira ransomware encryptorCISA AA24-109AJun 2023 – Aug 2025
HASH (SHA-256)dcfa2800754e5722acf94987bb03e814edcb9acebda37df6da1987bf48e5b05e — Win.exe, Akira ransomware encryptorCISA AA24-109AJun 2023 – Aug 2025
HASH (SHA-256)3298d203c2acb68c474e5fdad8379181890b4403d6491c523c13730129be3f75 — Akira_v2 ransomware (build 1)CISA AA24-109A2025
HASH (SHA-256)0ee1d284ed6630738720912c7bde7fac5ca1121403f1a5d2d5411317df282796c — Akira_v2 ransomware (build 2)CISA AA24-109A2025
HASH (SHA-256)2f629395fdfa11e713ea8bf11d40f6f240acf2f5fcf9a2ac50b6f7fbc7521c83 — Akira "Megazord" ransomware sample (1 of 11 published Megazord hashes; remainder in advisory Table 2, not reproduced here for brevity)CISA AA24-109A2023 – 2024
HASH (SHA-256)58359209e215a9fc0dafd14039121398559790dba9aa2398c457348ee1cb8a4d — Ladon.exe, Akira ransomware file (Nov 2025 update)CISA AA24-109A2025
HASH (SHA-256)cf3465d7e49b609defa1e2b6cfcc86ffa30c72246cb2744dbf50736c5f3d74d5 — qKtul.vbs, VBScript used by Akira threat actorsCISA AA24-109A2025
FILEfn.txt / akira_readme.txt — ransom note, dropped in C:\ root and every C:\Users\<user> directoryCISA AA24-109A / FBI reporting2023 – 2025
FILE EXT.akira / .powerranges / .akiranew / .aki — encrypted-file extension markersCISA AA24-109A2023 – 2025
CVECVE-2024-40766 — SonicWall SonicOS improper access control (CWE-284), CVSS 9.3 — current primary initial-access vectorSonicWall / CISA KEVDisclosed Aug 23, 2024
ACCOUNTitadm — recurring name for Akira-created domain administrator accountCISA AA24-109AObserved across multiple 2024–2025 intrusions
08
Analyst Assessment
Overall Threat LevelCRITICAL
Attribution ConfidenceMEDIUM (Conti-diaspora lineage) / HIGH (brand-to-infrastructure attribution)
TrajectoryEscalating — expanding hypervisor targeting, sustained CVE-driven access, no disruption to date
Most Dangerous CapabilitySpeed-to-impact: encryption in as little as ~55 minutes from initial access
Primary Intel GapNo published C2/staging infrastructure IOCs; no confirmed individual attribution
Ecosystem / Affiliated Groups
Conti (diaspora / successor lineage) Frag ransomware (shared infrastructure) Fog ransomware (on-chain overlap w/ Frag)

Akira warrants a CRITICAL threat-level rating on the strength of scale and tempo alone: $244.17 million in claimed proceeds, 1,584 cumulative leak-site victims as of August 2026, and a documented ability to move from initial VPN compromise to completed encryption in under an hour in at least one campaign. What elevates this beyond a typical high-volume RaaS profile is the group's demonstrated adaptability — expanding from Windows-only encryption in March 2023 to ESXi (April 2023), to a Rust-rewritten Akira_v2 encryptor with anti-analysis build-gating, to Nutanix AHV hypervisors (June 2025) — each expansion arriving roughly in step with, rather than lagging, broader industry adoption of the underlying virtualization platforms being targeted.

The central competing hypothesis worth stating plainly is whether "Akira is a Conti successor" describes organizational continuity (the same people, reconstituted) or merely personnel/tooling continuity within a much looser criminal labor market (former Conti-affiliated individuals now working across Akira, Fog, and Frag interchangeably as RaaS affiliates, without any of the three being a formal successor organization to Conti as an entity). The blockchain evidence — wallet-to-wallet Bitcoin transfers to known Conti leadership addresses — is genuinely strong for personnel/financial continuity but does not, on its own, resolve which hypothesis is correct; both are consistent with the available public evidence, and this profile does not assert one over the other beyond what TRM Labs' and Arctic Wolf's underlying data supports.

Forward risk trajectory is upward: Akira has absorbed market share vacated by LockBit, BlackCat/ALPHV, and Hive's respective law-enforcement disruptions without experiencing a comparable takedown itself, and its edge-device exploitation model (patch-lag-driven, not zero-day-dependent) is durable against any single vendor's remediation efforts. What would change this assessment: a law-enforcement seizure or public indictment — comparable to the OFAC actions that formally anchored several Conti/TrickBot members to named individuals in 2023 — would sharply increase attribution confidence and could meaningfully disrupt operational tempo, as it has for peer RaaS brands; absent that, independent researcher-driven decryption breakthroughs (a GPU brute-force method for the Linux/ESXi variant was published in 2024, and Avast has released a free Windows decryptor) represent the only public counter-pressure currently observed, and neither appears to have measurably slowed the group's leak-site posting rate through mid-2026.

09
Defensive Recommendations
01
Enforce phishing-resistant MFA (FIDO2/WebAuthn, not SMS/TOTP alone) on every VPN and remote-access service, with no exceptions for legacy/service accounts.
Counters: T1133, T1078, T1110.003
02
Prioritize patching the eight actively-weaponized CVEs, starting with CVE-2024-40766 (SonicWall, CVSS 9.3) and the Cisco ASA/FTD and Veeam Backup & Replication flaws named in CISA AA24-109A.
Counters: T1190
03
Allowlist and alert on RMM tool installation (AnyDesk, LogMeIn, RustDesk, MobaXterm); treat any unexpected new install on a server or domain controller as a high-priority alert.
Counters: T1219, T1021.001
04
Deploy Microsoft's vulnerable-driver blocklist (or equivalent WDAC policy) to prevent POORTRY-class BYOVD kernel-level EDR/AV termination.
Counters: T1068, T1562.001
05
Harden domain controller VM/hypervisor access — restrict console and snapshot/VMDK access to prevent offline NTDS.dit extraction; enable Credential Guard.
Counters: T1003.002, T1003.003
06
Maintain immutable, offline, regularly-tested backups. Akira's hybrid ChaCha20+RSA encryption offers no recovery path without the attacker's key; VSS-copy deletion is standard across intrusions.
Counters: T1486, T1490
07
Monitor and restrict outbound tunneling tools (Ngrok, Cloudflare Tunnel) via egress filtering, proxy inspection, and DNS monitoring for known tunneling-service domains.
Counters: T1572, T1090
08
Alert on anomalous RClone/WinSCP/FileZilla execution and outbound traffic to MEGA.nz or similar cloud-sync destinations as a leading exfiltration indicator.
Counters: T1567.002, T1048
10
OPSEC Procedures Observed infrastructure hygiene, rotation patterns, anti-forensics
Infrastructure Rotation [MEDIUM]
Minimal actor-registered infrastructure has been publicly documented — no IP/domain IOCs appear in the Nov 2025 CISA advisory. Akira relies almost entirely on legitimate third-party services (Ngrok, Cloudflare Tunnel, MEGA, AnyDesk, LogMeIn) rather than owned C2 domains or IPs, which functionally eliminates traditional infrastructure-rotation tradecraft as an observable OPSEC pattern — there is little dedicated infrastructure for defenders to track rotating in the first place.
Living-off-the-Land Ratio [HIGH]
Overwhelmingly LOTL-driven: the large majority of the documented toolchain (AnyDesk, LogMeIn, RustDesk, MobaXterm, PuTTY, Impacket, PowerShell, WMIC, Ngrok, cloudflared, RClone, WinSCP, FileZilla, 7-zip, AdFind, SoftPerfect NetScan) is legitimate commercial or open-source software. Custom/malicious development is largely confined to the encryptors themselves (Megazord, Akira_v2) plus the POORTRY/STONESTOP BYOVD pairing and the commodity SystemBC RAT — a deliberate choice that maximizes blending with normal administrator and IT-support activity.
Anti-Forensics Routines [MEDIUM]
Volume Shadow Copy Service deletion via vssadmin.exe/PowerShell is standard practice across intrusions to inhibit recovery and impede forensic reconstruction. No source-documented log-clearing, timestomping, or memory-only execution specifics beyond VSS deletion were identified in current reporting — stated as a gap rather than inferred.
Timing & Operational Patterns [LOW]
No source-documented beacon-jitter configuration or victim-timezone-relative work-hour data was identified in the reviewed reporting. What is documented is speed-of-execution rather than stealth-of-timing: encryption completed in as little as 55 minutes, and full exfiltration-to-encryption in "just over two hours" in some 2025 incidents (CISA AA24-109A) — suggesting an operational preference for rapid completion over prolonged, low-and-slow dwell time.
Tooling Hygiene [MEDIUM]
HeartCrypt, a commercial packer-as-a-service, is applied specifically to defeat static and behavioral detection ahead of payload delivery. The Akira_v2 encryptor's embedded Build ID execution gate — refusing to run without a matching identifier — functions as a distinct anti-sandbox/anti-research control layered on top of standard packing, indicating deliberate investment in complicating third-party sample analysis.
11
Detection Evasion Specific techniques, LOLBin sequences, EDR bypass patterns
BYOVD EDR/AV Termination T1068
EDR BYPASS POORTRY / STONESTOP
STONESTOP installs POORTRY — malware written as a signed, vulnerable Windows driver — to obtain kernel-mode (Ring 0) code execution and terminate EDR/AV processes operating above the driver's privilege level.
Per CISA AA24-109A Table 1: "POORTRY [is] malware written as a signed vulnerable Windows deriver [sic]. Akira threat actors used the malware to implement the Bring Your Own Vulnerable Driver (BYOVD) tactic." Specific load command, service-registration path, or driver-signing certificate details not publicly documented as of Nov 2025.
Legitimate-Driver AV Termination T1562.001
EDR BYPASS PowerTool / Zemana AntiMalware driver
Distinct from the POORTRY/STONESTOP pairing: PowerTool exploits the legitimate, signed Zemana AntiMalware driver — rather than a purpose-built malicious one — to terminate antivirus-related processes prior to encryption.
Specific IOCTL calls or exploitation sequence not publicly documented as of Nov 2025 — CISA's advisory names the technique and driver but not the precise low-level invocation.
Living-off-the-Land Remote Access T1219 / T1021.001
EDR BYPASS NETWORK
Uses commercial remote-access software (AnyDesk, LogMeIn, RustDesk, MobaXterm) already common in enterprise environments rather than custom C2 implants, denying defenders a malware-signature detection surface and blending lateral movement with legitimate helpdesk/administrator traffic patterns.
No source-documented specific configuration flags or deployment sequence beyond tool selection itself.
Encrypted Tunnel Egress T1572
NETWORK SIEM EVASION
Establishes outbound-only encrypted tunnels via Ngrok and Cloudflare Tunnel (cloudflared), avoiding any inbound firewall rule requirement and blending with legitimate developer/DevOps traffic to the same widely-used services — complicating both network-based detection and simple domain-reputation blocking.
Specific Ngrok/cloudflared invocation arguments and tunnel-naming conventions not publicly documented as of Nov 2025.
Commercial Payload Packing T1027
EDR BYPASS
HeartCrypt, a commercial packer-as-a-service, is applied to Akira payloads to defeat static signature and behavioral heuristic detection prior to delivery.
Specific packing/crypting parameters not publicly documented as of Nov 2025.
Anti-Analysis Build Gating Not formally ATT&CK-mapped
EDR BYPASS
The Rust-based Akira_v2 encryptor embeds a build identifier as a runtime execution condition, refusing to run without a matching ID — a bespoke anti-sandbox/anti-research control distinct from standard virtualization-detection techniques, making generic automated sandboxes ineffective against captured samples absent the correct build parameter.
Exact Build ID validation mechanism not publicly documented as of Nov 2025 — trusted third-party analysis confirmed the gate's existence and effect, not its internal implementation.
12
Emulation Resources MITRE CTID & Published Adversary Emulation Plans
MITRE CTID — ADVERSARY EMULATION PLAN Not Available
No MITRE CTID adversary emulation plan published for Akira as of 2026-09-03. The Center for Threat-Informed Defense's Adversary Emulation Library (confirmed via direct repository review) currently covers APT29, Blind Eagle, Carbanak Group, FIN6, FIN7, menuPass, OceanLotus, OilRig, Sandworm, Turla, and Wizard Spider as full emulation plans, plus a set of technique-focused micro-emulation plans — Akira is not among them.
Additional Emulation Resources
CISA
Advisory-embedded ATT&CK-mapped validation guidance · Accessed: 2026-09-03
AttackIQ
Vendor-published emulation/validation scenario mapped to the Nov 2025 advisory update · Accessed: 2026-09-03
Picus Security
Vendor threat-brief with simulation/detection guidance · Accessed: 2026-09-03
Gap Note
Atomic Red Team and SigmaHQ repositories were checked for Akira-specific content; GitHub's code-search interface requires authenticated access not available in this research session, so presence/absence of dedicated Atomic tests or Sigma rules could not be conclusively verified. Check redcanaryco/atomic-red-team and SigmaHQ/sigma directly for current coverage.
Verification incomplete · Noted 2026-09-03
13
References URLs are NOT defanged — navigate directly
CISA/FBI/DC3/HHS/Europol/OFAC/NCSC-NL
Orig. published Apr 18, 2024; updated Nov 13, 2025 · Accessed: 2026-09-03
MITRE ATT&CK
ATT&CK v18 · Accessed: 2026-09-03
MITRE ATT&CK
Accessed: 2026-09-03
Arctic Wolf Labs
Blockchain-transaction attribution analysis · Accessed: 2026-09-03
TRM Labs
Attribution / geolocation / financial analysis · Accessed: 2026-09-03
Unit 42 (Palo Alto)
Accessed: 2026-09-03
SecurityWeek
CVE-2023-20269 reporting · Accessed: 2026-09-03
ThreatMate
CVE-2020-3259 KEV addition · Accessed: 2026-09-03
GuidePoint Security
BYOVD/driver-abuse technical detail · Accessed: 2026-09-03
SC Media
Independent researcher decryption breakthrough · Accessed: 2026-09-03
TechRadar / Yahoo Tech
Nutanix AHV targeting expansion · Accessed: 2026-09-03
bushidotoken.net
Early tracking / Conti-lineage code analysis · Accessed: 2026-09-03
HIPAA Journal
Nov 2025 advisory-update reporting · Accessed: 2026-09-03