Akira
activeAlso known as: Akira Ransomware
Akira is a ransomware operation that emerged in March 2023 with a retro 1980s-themed leak site. The group primarily targets small to medium businesses and has been linked to the now-defunct Conti ransomware gang. They employ double extortion tactics and have shown rapid growth.
First Seen
2023-03
Last Activity
2025-01
Target Regions
3 regions
Industries
5 sectors
EducationFinanceReal EstateManufacturingHealthcare
Attack Chain (MITRE ATT&CK)
Visual representation of the attack phases and techniques used by Akira
Click on a phase to view details and MITRE ATT&CK technique IDs
Tactics & Techniques
MITRE ATT&CK mapped tactics and techniques used by this threat actor
| Technique ID | Name | Tactic | Description | Reference |
|---|---|---|---|---|
| T1190 | Exploit Public-Facing Application | Initial Access | Exploits Cisco VPN and SonicWall vulnerabilities | MITRE |
| T1078 | Valid Accounts | Initial Access | Uses compromised VPN credentials without MFA | MITRE |
| T1486 | Data Encrypted for Impact | Impact | ChaCha20/RSA encryption with .akira extension | MITRE |
Indicators of Compromise (IOCs)
Known IOCs associated with Akira operations
| Type | Value | Description | Last Seen | Actions |
|---|---|---|---|---|
| hash | 3c92bfc71004340ebc00146ced294bc94f49f6a5e212016ac05e7d10fcb3312c | Akira ransomware Windows variant | 2025-01-10 | |
| domain | akira[.]onion | Tor leak site | — | |
| filename | akira_readme.txt | Ransom note filename | — |
IOCs are defanged for safety. Click copy to get the clean value.
Detection Guidance
SIEM and EDR detection recommendations for identifying Akira activity
- 1Monitor for failed Cisco VPN authentication attempts
- 2Detect vssadmin.exe shadow copy deletion
- 3Alert on PowerShell with encoded commands
- 4Monitor for .akira file extension creation
Mitigation, Containment & Recovery
Step-by-step guidance for responding to and recovering from this ransomware attack
- 1Patch Cisco VPN to latest version
- 2Enable MFA on all VPN connections
- 3Isolate affected systems
