Megazord
MITRE ATT&CK: S1191 View on attack.mitre.org
Aliases: Megazord
- First seen
- 2023-08-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 13:23:39
Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality technology-and-telecommunications
Context
Megazord is a Rust-based variant of Akira ransomware that has been in use since at least August 2023 to target Windows environments. Megazord has been attributed to the Akira group based on overlapping infrastructure though is possibly not exclusive to the group.
Detection coverage
- 1 YARA rules
- 84 Sigma rules
Malware & tools used
- Windows Command Shell (attack-pattern)
- Service Stop (attack-pattern)
- Log Enumeration (attack-pattern)
- Process Discovery (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- File and Directory Discovery (attack-pattern)
Used by threat actors
- Akira (threat-actor)
Detection rules
- SIGNATURE_BASE_MAL_WIN_Megazord_Apr25 (yara-rule)
Reports & references
- Cisco Talos — Akira Ransomware Continues To Evolve (report)
- Palo Alto Unit 42 — Threat Assessment Howling Scorpius Akira Ransomware (report)
- CISA — Aa24 109A Stopransomware Akira Ransomware 2 (report)
- MITRE ATT&CK — S1191 (report)