01
Akira is a financially motivated ransomware-as-a-service operation.8
Active since March 2023, Akira uses affiliates to conduct intrusions and extortion rather than operating as one uniform intrusion team.
CARDS
Akira is a financially motivated ransomware-as-a-service operation active since March 2023. It combines data theft with encryption and has repeatedly used remote-access and valid-account paths to enter victim networks. Separate 2025 reporting supports Akira use of SonicWall SSLVPN access, including CVE-2024-40766 exposure, legacy or unreset migration credentials, TOTP enrollment, and LDAP authorization weaknesses. The distinct July 25–27, 2026 SonicWall credential-stuffing campaign is unattributed, and no public evidence reviewed connects Akira to the MySonicWall cloud-backup theft.
Directory Briefing
01
Active since March 2023, Akira uses affiliates to conduct intrusions and extortion rather than operating as one uniform intrusion team.
02
Akira uses double extortion: affiliates steal data before encrypting systems, so containment, breach analysis, and recovery must begin together.
03
The joint advisory associates Akira with valid accounts and external remote services, making VPN and identity evidence critical during initial triage.
04
Government reporting specifically identifies Akira access through VPN services lacking multifactor authentication; enforce MFA and investigate unexpected remote sessions.
05
Akira has Windows tooling and a Linux variant designed to affect VMware ESXi virtual machines, expanding potential impact from endpoints to concentrated virtual infrastructure.
06
Published Akira reporting includes credential-access and exfiltration tooling, so responders should hunt for account misuse, archive creation, and outbound transfer activity before the ransomware event.
07
The advisory describes attempts to inhibit system recovery; defenders should isolate and verify offline backups before relying on them during restoration.
08
Tietoevry confirmed that Akira affected a Swedish datacenter during January 19–20, 2024 and said a limited number of customers in Sweden were impacted.
09
Rapid7 reported Akira activity involving SonicWall devices, reinforcing the need to patch exposed appliances and rotate or invalidate inherited credentials.
10
A known Akira access pattern does not prove that every SonicWall credential attack or cloud-backup incident involved Akira; attribution requires incident-specific evidence.
Bottom Line Up Front
It has operated since March 2023. Affiliates steal data and encrypt systems, so recovery and breach analysis must begin together rather than treating encryption as the whole incident.
Government reporting associates Akira with external remote services and compromised credentials, including single-factor VPN access. Preserve VPN, identity, and administrator-session evidence first.
Published reporting covers Windows systems and a Linux variant targeting VMware ESXi, creating concentrated outage risk across endpoints, servers, and virtual infrastructure.
Rapid7 documented Akira use of SonicWall access paths, but that history does not by itself connect Akira to every SonicWall credential attack or cloud-backup incident.
Decision Context
Akira is a financially motivated ransomware-as-a-service operation active since March 2023. It combines data theft with encryption and has repeatedly used remote-access and valid-account paths to enter victim networks. Separate 2025 reporting supports Akira use of SonicWall SSLVPN access, including CVE-2024-40766 exposure, legacy or unreset migration credentials, TOTP enrollment, and LDAP authorization weaknesses. The distinct July 25–27, 2026 SonicWall credential-stuffing campaign is unattributed, and no public evidence reviewed connects Akira to the MySonicWall cloud-backup theft.1,3,2
Actor Card Detail
Remote access and VPN, valid accounts, identity, endpoints, virtualization, backups, and sensitive data.
Victimology
Tietoevry publicly confirmed that an Akira ransomware attack affected one of its Swedish datacenters during the night of January 19–20, 2024. The company said the affected platform was isolated and a limited number of customers in Sweden were impacted.
Identity
Targeting
Target Countries / Exposure1,2
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| akira Ransomware / Extortion Operations12 | akira Ransomware / Extortion Operations is retained in the campaign database for akira. The Akira ransomware group is said to have emerged in March 2023, and there's much speculation about its ties to the former CONTI ransomware group.<br> <br> It's worth noting that with the end of CONTI's operation, several affiliates migrated to independent campaigns such as Royal, BlackBasta, and others.<br> <br> According to some reports, Akira affiliates also work with other ransomware operations, such as Snatch and BlackByte, as an open directory of tools used by an Akira operator was identified, which also... |
Indicators
SOCRadar reports 3456 IOCs for this profile. IntelliOS currently retains 39 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 4 source groups tracked; 1 currently contributes retained observable or context rows.
Retained Observables
Showing 39 of 39
| Type | Value | Source |
|---|---|---|
| SHA-256 Hash | 0ee1d284ed663073872012c7bde7fac5ca1121403f1a5d2d5411317df282796c10 | CISA AA24-109A |
| SHA-256 Hash | 131da83b521f610819141d5c740313ce46578374abb22ef504a7593955a65f0710 | CISA AA24-109A |
| SHA-256 Hash | 18051333e658c4816ff3576a2e9d97fe2a1196ac0ea5ed9ba386c46defafdb8810 | CISA AA24-109A |
| SHA-256 Hash | 3298d203c2acb68c474e5fdad8379181890b4403d6491c523c13730129be3f7510 | CISA AA24-109A |
| SHA-256 Hash | 58359209e215a9fc0dafd14039121398559790dba9aa2398c457348ee1cb8a4d10 | CISA AA24-109A |
| SHA-256 Hash | 58afef43cec0ee7a2fbfd9cdd5b71f55f971672d5e523a400b82b98c752ca5b710 | CISA AA24-109A |
| SHA-256 Hash | 9f393516edf6b8e011df6ee991758480c5b99a0efbfd68347786061f0e04426c10 | CISA AA24-109A |
| SHA-256 Hash | aaa6041912a6ba3cf167ecdb90a434a62feaf08639c59705847706b9f492015d10 | CISA AA24-109A |
| SHA-256 Hash | cf3465d7e49b609defa1e2b6cfcc86ffa30c72246cb2744dbf50736c5f3d74d510 | CISA AA24-109A |
| SHA-256 Hash | CFA209D56E296C40B32815270060E539963D68CDA3285C5F393C97EB3C960D3710 | CISA AA24-109A |
| SHA-256 Hash | d2fd0654710c27dcf37b6c1437880020824e161dd0bf28e3a133ed777242a0ca10 | CISA AA24-109A |
| SHA-256 Hash | dcfa2800754e5722acf94987bb03e814edcb9acebda37df6da1987bf48e5b05e10 | CISA AA24-109A |
| SHA-256 Hash | dfe6fddc67bdc93b9947430b966da2877fda094edf3e21e6f0ba98a84bc5319810 | CISA AA24-109A |
| SHA-256 Hash | ffd9f58e5fe8502249c67cad0123ceeeaa6e9f69b4ec9f9e21511809849eb8fc10 | CISA AA24-109A |
| SHA-1 Hash | 5961a99181df157b81d35a50eeb27f96577a2fa210 | CISA AA24-109A |
| SHA-1 Hash | ef328f68c6d865ba4ef4223b5d8ee9efb566742010 | CISA AA24-109A |
| MD5 Hash | 17c624693f5dd575485ec4286b0ba78610 | CISA AA24-109A |
| MD5 Hash | 57D1AEB41D9CFEA4D6899724BC4B09A510 | CISA AA24-109A |
| Filename | 123.zip10 | CISA AA24-109A |
| Filename | Akira_v210 | CISA AA24-109A |
| Filename | All.bat10 | CISA AA24-109A |
| Filename | Ladon.exe10 | CISA AA24-109A |
| Filename | Megazord10 | CISA AA24-109A |
| Filename | qKtul.vbs10 | CISA AA24-109A |
| Filename | s64.dll10 | CISA AA24-109A |
| Filename | snaffler.exe10 | CISA AA24-109A |
| Filename | Veeam-Get-Creds.ps110 | CISA AA24-109A |
| Filename | VeeamHax.exe10 | CISA AA24-109A |
| Filename | Vmware.exe10 | CISA AA24-109A |
| Filename | w.exe10 | CISA AA24-109A |
| Filename | win_locker.exe10 | CISA AA24-109A |
| Filename | Win.exe10 | CISA AA24-109A |
| Tool / Process | AnyDesk10 | CISA AA24-109A |
| Tool / Process | FileZilla10 | CISA AA24-109A |
| Tool / Process | Mimikatz10 | CISA AA24-109A |
| Tool / Process | Ngrok10 | CISA AA24-109A |
| Tool / Process | PowerTool10 | CISA AA24-109A |
| Tool / Process | Rclone10 | CISA AA24-109A |
| Tool / Process | WinRAR10 | CISA AA24-109A |
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar2 | 3456 | 0 | Reported IOC count retained; underlying SOCRadar feed values are not republished unless stored as cited public observables. |
| CISA/FBI/DC3/HHS/Europol10 | N/A | 39 | Public observables or source-context rows retained and displayed. |
| MITRE ATT&CK3 | N/A | 0 | Context source retained; no direct observable rows retained from this source yet. |
| CrowdStrike11 | N/A | 0 | Context source retained; no direct observable rows retained from this source yet. |
Actor Chronology
| Date | Event | Evidence Boundary |
|---|---|---|
| 2023-033 | Akira activity begins | MITRE ATT&CK and the joint CISA advisory place Akira activity in or from March 2023. |
| 2023-048 | Linux and VMware ESXi variant observed | The joint CISA advisory states that an Akira Linux variant targeting VMware ESXi virtual machines was observed beginning in April 2023. |
| 2023-088 | Megazord used in some Akira attacks | The joint CISA advisory states that, beginning in August 2023, some Akira attacks used the Megazord ransomware variant. |
| 2024-01-199 | Tietoevry Swedish datacenter incident begins | Tietoevry confirmed that an Akira ransomware attack affected one of its Swedish datacenters during the night of January 19–20, 2024. |
| 2025-087 | Akira campaign targets SonicWall devices | Rapid7 reported an Akira campaign targeting SonicWall devices and later described incident-response observations involving SonicWall appliances. |
Source-Backed Questions
Akira is a financially motivated ransomware-as-a-service operation active since March 2023. Its affiliates steal data and encrypt systems to support double extortion.
Government reporting associates Akira with compromised credentials used against external remote services, including single-factor VPN access. Incident-specific entry paths can vary by affiliate.
Published analysis covers Windows systems and Linux variants capable of targeting VMware ESXi virtual machines.
The joint advisory prioritizes multifactor authentication, timely remediation of known exploited vulnerabilities, network segmentation, offline backups, and monitoring for unauthorized remote access and credential use.
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Akira | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | Akira | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Akira, then compares naming and aliases against SOCRadar Actor Alias Index where collision checks exist.
The retained collision rows point to possible boundary questions involving akira / Storm-1567 based on shared evidence such as akira, Storm-1567, GOLD SAHARA, PUNK SPIDER, Howling Scorpius. These notes preserve reader context; IntelliOS does not automatically merge actor records.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| SOCRadar Actor Alias Index possible same actor | akira / Storm-1567 | akira, Storm-1567, GOLD SAHARA, PUNK SPIDER, Howling Scorpius | Retain as a source-boundary note; do not merge automatically. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Threat actor directory source for profile fields and reported activity. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/akira | Actor-specific source for ransomware profile metadata and reported IOC counts when available. |
| 3 | MITRE ATT&CK https://attack.mitre.org/groups/G1024/ | ATT&CK source for group, campaign, software, alias, and technique mappings where matched. |
| 4 | MITRE CTI https://raw.githubusercontent.com/mitre/cti/master/enterprise-attack/enterprise-attack.json | Open MITRE CTI source for ATT&CK data. |
| 5 | SonicWall Credential Attacks Flash Brief /vault/sonicwall-credential-stuffing-cloud-backup-risk | IntelliOS Flash Threat Brief |
| 6 | 2026 SonicWall Credential-Stuffing Campaign /threat-actor-cards/campaigns/sonicwall-credential-stuffing-july-2026 | CARDS Campaign |
| 7 | Rapid7: Akira Utilizing SonicWall Devices https://www.rapid7.com/blog/post/dr-akira-ransomware-group-utilizing-sonicwall-devices-for-initial-access/ | Primary Incident Research |
| 8 | CISA/FBI/EC3/NCSC-NL: Akira Ransomware https://www.cisa.gov/sites/default/files/2024-04/aa24-109a-stopransomware-akira-ransomware_2.pdf | Joint Cybersecurity Advisory |
| 9 | Tietoevry: Confirmed Akira Ransomware Incident https://www.tietoevry.com/en/newsroom/all-news-and-releases/press-releases/2024/01/tietoevry-ransomware-attack-in-sweden--restoration-work-progressing/ | First-Party Victim Disclosure |
| 10 | CISA AA24-109A: StopRansomware Akira Ransomware https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-109a | IOC Source |
| 11 | CrowdStrike Adversary Universe: PUNK SPIDER https://www.crowdstrike.com/adversaries/punk-spider/ | Threat Actor Profile |
| 12 | akira - Ransomware.live group profile https://www.ransomware.live/group/akira | Ransomware.live campaign row source for akira Ransomware / Extortion Operations. |