Akira Ransomware

Description Summary

Akira is a ransomware family that emerged in March 2023 and quickly became one of the most active extortion brands of 2023–2024. It uses double extortion, hosts a retro green-on-black Tor leak site, and has both Windows and Linux/ESXi encryptors. CISA assesses Akira affiliates have impacted over 250 organizations and claimed roughly USD 42 million in ransom payments.

Threat Actor

The Akira group is believed to overlap with former Conti members. Affiliates frequently abuse Cisco ASA/FTD VPN appliances lacking MFA (CVE-2023-20269), valid credentials, and SonicWall SSL-VPN flaws for initial access.

Technical Indicators

Encryption Extension
.akira / .powerranges (older Megazord variant)
Encryption Algorithm
ChaCha20 (file content) + RSA-4096 (key wrapping)
Ransom Note Name
akira_readme.txt
Targeted Industries
Manufacturing, Education, Financial, Real estate, Healthcare
First Seen
March 2023
Last Seen
Active (continued activity through 2024–2025)
Geographical Location
North America, Europe, Australia

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 4 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
T1190 Exploit Public-Facing Application (Cisco ASA)
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 4 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop
T1486 Data Encrypted for Impact (ChaCha20+RSA)
Credential Access x 1 T1003.001 OS Credential Dumping: LSASS Memory