CARDS
CARDS
The Akira ransomware group is said to have emerged in March 2023, and there's much speculation about its ties to the former CONTI ransomware group.<br> <br> It's worth noting that with the end of CONTI's operation, several affiliates migrated to independent campaigns such as Royal, BlackBasta, and others.<br> <br> According to some reports, Akira affiliates also work with other ransomware operations, such as Snatch and BlackByte, as an open directory of tools used by an Akira operator was identified, which also...
Last updated May 24, 2026, 8:00 PM EDT
Evidence Boundary
Bottom Line Up Front
The Akira ransomware group is said to have emerged in March 2023, and there's much speculation about its ties to the former CONTI ransomware group.<br> <br> It's worth noting that with the end of CONTI's operation, several affiliates migrated to independent campaigns such as Royal, BlackBasta, and others.<br> <br> According to some reports, Akira affiliates also work with other ransomware operations, such as Snatch and BlackByte, as an open directory of tools used by an Akira operator was identified, which also...[1]
Data theft, encryption, business interruption, extortion pressure, and notification/legal exposure depending on victim environment.[1]
Harden exposed remote access Monitor archive creation and mass file reads Protect backups Prepare extortion communications workflow[1]
Decision Summary
The Akira ransomware group is said to have emerged in March 2023, and there's much speculation about its ties to the former CONTI ransomware group.<br> <br> It's worth noting that with the end of CONTI's operation, several affiliates migrated to independent campaigns such as Royal, BlackBasta, and others.<br> <br> According to some reports, Akira affiliates also work with other ransomware operations, such as Snatch and BlackByte, as an open directory of tools used by an Akira operator was identified, which also...
The retained record scopes this as ransomware / extortion / cybercrime activity during Operational window varies by public reporting. Data theft, encryption, business interruption, extortion pressure, and notification/legal exposure depending on victim environment.[1]
Harden exposed remote access Monitor archive creation and mass file reads Protect backups Prepare extortion communications workflow[1]
Confirmed reporting is separated from attribution, victim, and prevalence claims that the retained sources do not establish. Confidence: Medium for public ransomware ecosystem tracking; individual claims and victim listings require local/source corroboration..[1]
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
Ransomware group and victim claims are often adversary-controlled. Validate actor linkage, malware, and impact with incident evidence.
IntelliOS
None Found
Citations