Akira
MITRE ATT&CK: G1024 View on attack.mitre.org
Aliases: GOLD SAHARA, PUNK SPIDER, Howling Scorpius, Akira
- First seen
- 2023-03-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- criminal
- Related IoCs
- 335 (334 malicious)
- Last IoC activity
- 2026-09-01 23:56:54
- Profile updated
- 2026-07-07 12:13:18
Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications
Context
Akira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.
Recent IoC activity
334 malicious indicators in Maltiverse are attributed to Akira (G1024). The 20 most recently updated:
Detection coverage
- 15 YARA rules
- 529 Sigma rules
Malware & tools used
- Exfiltration to Cloud Storage (attack-pattern)
- Sharepoint (attack-pattern)
- Account Access Removal (attack-pattern)
- Domain Trust Discovery (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Valid Accounts (attack-pattern)
- Steal or Forge Kerberos Tickets (attack-pattern)
- Remote System Discovery (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- PowerShell (attack-pattern)
- Financial Theft (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- External Remote Services (attack-pattern)
- Binary Padding (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Remote Access Tools (attack-pattern)
- Archive via Utility (attack-pattern)
- Megazord (malware)
- Rclone (malware)
- Akira (malware)
- Akira _v2 (malware)
- Mimikatz (malware)
- LaZagne (malware)
- AdFind (malware)
- PsExec (malware)
Related threat objects
- Storm-1567 (threat-actor)
Reports & references
- news.sophos.com — Cryptoguard An Asymmetric Approach To The Ransomware Battle (report)
- Kaspersky — 111483 (report)
- trellix.com — Akira Ransomware (report)
- blog.sekoia.io — Sekoia Io Mid 2023 Ransomware Threat Landscape (report)
- decoded.avast.io — Avast Q2 2023 Threat Report (report)
- arcticwolf.com — Conti And Akira Chained Together (report)
- MITRE ATT&CK — G1024 (report)
- blog.bushidotoken.net — Tracking Adversaries Akira Another (report)
- Cisco Talos — Akira Ransomware Continues To Evolve (report)
- Palo Alto Unit 42 — Threat Assessment Howling Scorpius Akira Ransomware (report)
- CISA — Aa24 109A Stopransomware Akira Ransomware 2 (report)
- CrowdStrike — Punk Spider (report)
- secureworks.com — Gold Sahara (report)
External references
- mitre-attack — G1024
- PUNK SPIDER
- Howling Scorpius
- GOLD SAHARA
- CISA Akira Ransomware APR 2024
- CrowdStrike PUNK SPIDER
- Cisco Akira Ransomware OCT 2024
- Secureworks GOLD SAHARA
- Arctic Wolf Akira 2023
- BushidoToken Akira 2023
- Palo Alto Howling Scorpius DEC 2024
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy