Megazord

MITRE ATT&CK: S1191 View on attack.mitre.org

Aliases: Megazord

First seen
2023-08-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:23:39

Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality technology-and-telecommunications

Context

Megazord is a Rust-based variant of Akira ransomware that has been in use since at least August 2023 to target Windows environments. Megazord has been attributed to the Akira group based on overlapping infrastructure though is possibly not exclusive to the group.

Detection coverage

  • 1 YARA rules
  • 84 Sigma rules

Malware & tools used

  • Windows Command Shell (attack-pattern)
  • Service Stop (attack-pattern)
  • Log Enumeration (attack-pattern)
  • Process Discovery (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • File and Directory Discovery (attack-pattern)

Used by threat actors

Detection rules

  • SIGNATURE_BASE_MAL_WIN_Megazord_Apr25 (yara-rule)

Reports & references

  • Cisco Talos — Akira Ransomware Continues To Evolve (report)
  • Palo Alto Unit 42 — Threat Assessment Howling Scorpius Akira Ransomware (report)
  • CISA — Aa24 109A Stopransomware Akira Ransomware 2 (report)
  • MITRE ATT&CK — S1191 (report)

External references