CARDS
CARDS
Akira is a ransomware-as-a-service (RaaS) operation that first emerged in March 2023, rapidly gaining notoriety for its targeted attacks against organizations globally. The group's operational model evolved from an initial focus on Windows systems to deploying a Linux variant targeting VMware ESXi virtual machines in April 2023, and later expanding to Nutanix AHV systems. While the current Akira group is distinct from an older ransomware variant sharing the same name from 2017, it is assessed with moderate confidence to be of Russian or broader post-Soviet origin, evidenced by observations of the group communicating in Russian on dark web forums. Akira's primary motivation is financial gain through its double extortion scheme. A distinctive characteristic of Akira is the retro aesthetic of its data leak site, designed to resemble 1980s green-screen consoles. The group is notably efficient, capable of moving from initial access to full network encryption in under four hours. Akira ransomware threat actors are associated with other groups known as Storm-1567, Howling Scorpius, Punk Spider, and Gold Sahara, and have suspected connections to the defunct Conti ransomware group based on technical and operational similarities.
This profile is generated from the same canonical actor-card record used by the Threat Actor Cards directory, so aliases, targeting fields, activity notes, and source links stay aligned as the database is enriched.
Actor Card Detail
Identity
Targeting
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| akira Ransomware / Extortion Operations7 | akira Ransomware / Extortion Operations is retained in the campaign database for akira. The Akira ransomware group is said to have emerged in March 2023, and there's much speculation about its ties to the former CONTI ransomware group.<br> <br> It's worth noting that with the end of CONTI's operation, several affiliates migrated to independent campaigns such as Royal, BlackBasta, and others.<br> <br> According to some reports, Akira affiliates also work with other ransomware operations, such as Snatch and BlackByte, as an open directory of tools used by an Akira operator was identified, which also... |
Indicators
SOCRadar reports 3456 IOCs for this profile. IntelliOS currently retains 39 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 4 source groups tracked; 1 currently contributes retained observable or context rows.
Retained Observables
Showing 39 of 39
| Type | Value | Source |
|---|---|---|
| SHA-256 Hash | 0ee1d284ed663073872012c7bde7fac5ca1121403f1a5d2d5411317df282796c5 | CISA AA24-109A |
| SHA-256 Hash | 131da83b521f610819141d5c740313ce46578374abb22ef504a7593955a65f075 | CISA AA24-109A |
| SHA-256 Hash | 18051333e658c4816ff3576a2e9d97fe2a1196ac0ea5ed9ba386c46defafdb885 | CISA AA24-109A |
| SHA-256 Hash | 3298d203c2acb68c474e5fdad8379181890b4403d6491c523c13730129be3f755 | CISA AA24-109A |
| SHA-256 Hash | 58359209e215a9fc0dafd14039121398559790dba9aa2398c457348ee1cb8a4d5 | CISA AA24-109A |
| SHA-256 Hash | 58afef43cec0ee7a2fbfd9cdd5b71f55f971672d5e523a400b82b98c752ca5b75 | CISA AA24-109A |
| SHA-256 Hash | 9f393516edf6b8e011df6ee991758480c5b99a0efbfd68347786061f0e04426c5 | CISA AA24-109A |
| SHA-256 Hash | aaa6041912a6ba3cf167ecdb90a434a62feaf08639c59705847706b9f492015d5 | CISA AA24-109A |
| SHA-256 Hash | cf3465d7e49b609defa1e2b6cfcc86ffa30c72246cb2744dbf50736c5f3d74d55 | CISA AA24-109A |
| SHA-256 Hash | CFA209D56E296C40B32815270060E539963D68CDA3285C5F393C97EB3C960D375 | CISA AA24-109A |
| SHA-256 Hash | d2fd0654710c27dcf37b6c1437880020824e161dd0bf28e3a133ed777242a0ca5 | CISA AA24-109A |
| SHA-256 Hash | dcfa2800754e5722acf94987bb03e814edcb9acebda37df6da1987bf48e5b05e5 | CISA AA24-109A |
| SHA-256 Hash | dfe6fddc67bdc93b9947430b966da2877fda094edf3e21e6f0ba98a84bc531985 | CISA AA24-109A |
| SHA-256 Hash | ffd9f58e5fe8502249c67cad0123ceeeaa6e9f69b4ec9f9e21511809849eb8fc5 | CISA AA24-109A |
| SHA-1 Hash | 5961a99181df157b81d35a50eeb27f96577a2fa25 | CISA AA24-109A |
| SHA-1 Hash | ef328f68c6d865ba4ef4223b5d8ee9efb56674205 | CISA AA24-109A |
| MD5 Hash | 17c624693f5dd575485ec4286b0ba7865 | CISA AA24-109A |
| MD5 Hash | 57D1AEB41D9CFEA4D6899724BC4B09A55 | CISA AA24-109A |
| Filename | 123.zip5 | CISA AA24-109A |
| Filename | Akira_v25 | CISA AA24-109A |
| Filename | All.bat5 | CISA AA24-109A |
| Filename | Ladon.exe5 | CISA AA24-109A |
| Filename | Megazord5 | CISA AA24-109A |
| Filename | qKtul.vbs5 | CISA AA24-109A |
| Filename | s64.dll5 | CISA AA24-109A |
| Filename | snaffler.exe5 | CISA AA24-109A |
| Filename | Veeam-Get-Creds.ps15 | CISA AA24-109A |
| Filename | VeeamHax.exe5 | CISA AA24-109A |
| Filename | Vmware.exe5 | CISA AA24-109A |
| Filename | w.exe5 | CISA AA24-109A |
| Filename | win_locker.exe5 | CISA AA24-109A |
| Filename | Win.exe5 | CISA AA24-109A |
| Tool / Process | AnyDesk5 | CISA AA24-109A |
| Tool / Process | FileZilla5 | CISA AA24-109A |
| Tool / Process | Mimikatz5 | CISA AA24-109A |
| Tool / Process | Ngrok5 | CISA AA24-109A |
| Tool / Process | PowerTool5 | CISA AA24-109A |
| Tool / Process | Rclone5 | CISA AA24-109A |
| Tool / Process | WinRAR5 | CISA AA24-109A |
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar2 | 3456 | 0 | Reported IOC count retained; underlying SOCRadar feed values are not republished unless stored as cited public observables. |
| CISA/FBI/DC3/HHS/Europol5 | N/A | 39 | Public observables or source-context rows retained and displayed. |
| MITRE ATT&CK3 | N/A | 0 | Context source retained; no direct observable rows retained from this source yet. |
| CrowdStrike6 | N/A | 0 | Context source retained; no direct observable rows retained from this source yet. |
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Akira | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | Akira | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Baseline actor-card corpus source for retained profile fields. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/akira | Per-actor SOCRadar profile source for ransomware profile metadata and IOC count when available. |
| 3 | MITRE ATT&CK https://attack.mitre.org/groups/G1024 | Canonical ATT&CK group, campaign, software, aliases, and technique mapping source where matched. |
| 4 | MITRE CTI https://raw.githubusercontent.com/mitre/cti/master/enterprise-attack/enterprise-attack.json | Open MITRE CTI source used for ATT&CK enrichment. |
| 5 | CISA AA24-109A: StopRansomware Akira Ransomware https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-109a | IOC Source |
| 6 | CrowdStrike Adversary Universe: PUNK SPIDER https://www.crowdstrike.com/adversaries/punk-spider/ | Threat Actor Profile |
| 7 | akira - Ransomware.live group profile https://www.ransomware.live/group/akira | Ransomware.live campaign row source for akira Ransomware / Extortion Operations. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Akira, then compares naming and aliases against SOCRadar Actor Alias Index where collision checks exist.
The retained collision rows point to possible boundary questions involving akira / Storm-1567 based on shared evidence such as akira, Storm-1567, GOLD SAHARA, PUNK SPIDER, Howling Scorpius. These notes preserve reader context; IntelliOS does not automatically merge actor records.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| SOCRadar Actor Alias Index possible same actor | akira / Storm-1567 | akira, Storm-1567, GOLD SAHARA, PUNK SPIDER, Howling Scorpius | Retain as a source-boundary note; do not merge automatically. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |