Ako

Aliases: MedusaReborn

Malware type
ransomware, worm
Family
Malware family
Last IoC activity
2026-06-03 02:50:49
Profile updated
2026-07-07 13:48:42

Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing professional-services

Context

Once installed, Ako will attempt to delete Volume Shadow Copies and disable recovery services. It will then begin to encrypt all files that do not match a hard-coded list using an unknown algorithm. Whilst this is happening, Ako will scan the affected network for any connected devices or drives for it to propagate to.

Reports & references

  • digital.nhs.uk — Cc 3345 (report)
  • pcrisk.com — 16737 Ako Ransomware (report)
  • pcrisk.com — Ako Ransom Note Second Variant.Jpg (report)
  • pcrisk.com — Ako Ransomware Update 2020 04 09 Text File.Jpg (report)
  • pcrisk.com — Ako Update 2020 04 21 Text File.Jpg (report)
  • pcrisk.com — Ako Update 2020 04 21 Html File.Jpg (report)
  • pcrisk.com — Ako Ransomware Update 2020 10 15 Text File.Gif (report)
  • ransomlook.io — Ako (report)
  • tripwire.com — Ako Ransomware Using Spam Attachments To Target Networks (report)
  • attackiq.com — Emulating Ako Ransomware (report)
  • sonicwall.com — Ako Ransomware Demands 3000 Operators Hide Behind Tor (report)

External references