Akira _v2
MITRE ATT&CK: S1194 View on attack.mitre.org
Aliases: Akira _v2
- First seen
- 2024-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:23:37
Targeted industries: technology-and-telecommunications financial-services healthcare-and-pharmaceutical
Context
Akira _v2 is a Rust-based variant of Akira ransomware that has been in use since at least 2024. Akira _v2 is designed to target VMware ESXi servers and includes a new command-line argument set and other expanded capabilities.
Detection coverage
- 60 Sigma rules
Malware & tools used
- Create or Modify System Process (attack-pattern)
- Log Enumeration (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Service Stop (attack-pattern)
- Execution Guardrails (attack-pattern)
Used by threat actors
- Akira (threat-actor)
Reports & references
- Cisco Talos — Akira Ransomware Continues To Evolve (report)
- Palo Alto Unit 42 — Threat Assessment Howling Scorpius Akira Ransomware (report)
- CISA — Aa24 109A Stopransomware Akira Ransomware 2 (report)
- MITRE ATT&CK — S1194 (report)