Ako
Aliases: MedusaReborn
- Malware type
- ransomware, worm
- Family
- Malware family
- Last IoC activity
- 2026-06-03 02:50:49
- Profile updated
- 2026-07-07 13:48:42
Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing professional-services
Context
Once installed, Ako will attempt to delete Volume Shadow Copies and disable recovery services. It will then begin to encrypt all files that do not match a hard-coded list using an unknown algorithm. Whilst this is happening, Ako will scan the affected network for any connected devices or drives for it to propagate to.
Reports & references
- digital.nhs.uk — Cc 3345 (report)
- pcrisk.com — 16737 Ako Ransomware (report)
- pcrisk.com — Ako Ransom Note Second Variant.Jpg (report)
- pcrisk.com — Ako Ransomware Update 2020 04 09 Text File.Jpg (report)
- pcrisk.com — Ako Update 2020 04 21 Text File.Jpg (report)
- pcrisk.com — Ako Update 2020 04 21 Html File.Jpg (report)
- pcrisk.com — Ako Ransomware Update 2020 10 15 Text File.Gif (report)
- ransomlook.io — Ako (report)
- tripwire.com — Ako Ransomware Using Spam Attachments To Target Networks (report)
- attackiq.com — Emulating Ako Ransomware (report)
- sonicwall.com — Ako Ransomware Demands 3000 Operators Hide Behind Tor (report)