🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
AKIRA RANSOMWARE

/actor/akira-ransomware/  ·  0 intel reports

Year Established
2023
Attribution
Unknown (Eastern European Suspected)
Motivation
Financial
Modus Operandi (MO)
Double-extortion RaaS, Cisco VPN exploitation, retro-aesthetic branding
Primary Aliases
Akira

Akira Ransomware is a double-extortion ransomware operation that emerged in March 2023 and rapidly established itself as a significant player in the ransomware ecosystem, distinguished by its distinctive retro-terminal aesthetic on its data leak website , a stylistic choice that generated considerable media attention and helped differentiate the group within the saturated ransomware market.

Akira's primary initial access vector has been the exploitation of vulnerabilities in Cisco VPN and ASA products , particularly targeting accounts without multi-factor authentication configured , enabling the group to gain direct authenticated access to corporate networks through legitimate remote access infrastructure. This targeting of network perimeter devices reflects a sophisticated understanding of enterprise security architecture and the high value of VPN-level access for subsequent lateral movement.

The group has claimed attacks against hundreds of organisations across healthcare, education, financial services, and manufacturing globally, with a notable concentration of victims in North America and Europe. Akira's ransom demands typically range from $200,000 to millions of dollars, calibrated based on the victim's revenue and the sensitivity of exfiltrated data.

Security researchers identified code similarities between Akira's early encryptor and the Conti ransomware family , including shared code patterns suggesting either former Conti developers or access to Conti source code. A Linux variant targeting VMware ESXi environments was subsequently released, extending the group's capability to encrypt virtualised infrastructure. CISA, the FBI, and international partners issued a joint advisory about Akira in April 2024, having observed the group compromising over 250 organisations and collecting over $42 million in ransom payments.

Tactical Telemetry and Extortion Framework: In confirmed intrusions, Akira Ransomware employs double-extortion tactics, combining high-speed asymmetric encryption with automated data exfiltration pipelines. Initial access is routinely obtained via compromised Remote Desktop Protocol (RDP) credentials, initial access broker (IAB) marketplaces, and spear-phishing campaigns delivering infostealer payloads. Organizations operating critical IT infrastructure are advised to enforce strict network segmentation, deploy hardware-backed multi-factor authentication across all external access points, and maintain immutable offline backups to mitigate operational disruption.

STATUS: ACTIVE CLASSIFICATION: RANSOMWARE SYNDICATE LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles