Akira Ransomware | Guide to the Group, TTPs, SonicWall/Cisco Attacks, CISA & FBI Advisories, and Recovery

What Is Akira Ransomware?
Akira ransomware is a ransomware-as-a-service (RaaS) operation active since March 2023 that steals a victim’s data and then encrypts their systems to force payment. As of late September 2025, it had claimed about $244.17 million in ransomware proceeds. It has become one of the most financially successful extortion operations of the past three years.
Akira Ransomware Definition and Overview
Akira is both a malware family and the criminal operation behind it. Its tooling has grown from Windows-only encryptors to variants that hit Linux, VMware ESXi, Hyper-V, and Nutanix AHV virtual machines.
Ransomware-as-a-Service (RaaS) Model Explained
Under the RaaS model, multiple adversaries deploy the ransomware in exchange for a share of the proceeds. The core team maintains the encryptor and leak site, while affiliates run the intrusions. This is why Akira’s intrusions vary so much from one victim to the next.
Double Extortion: Encryption Plus Data Theft
Akira steals data before it encrypts anything. Victims who can restore from backups still face the threat of a public leak. Reporting suggests only about 25% of victims now agree to pay, which pushes the group to lean harder on stolen data as leverage.
Akira, Fog, and Related Ransomware Families
Akira is a distinct operation from Fog, another RaaS family that often appears in the same discussions because both favor VPN-based entry. Akira’s own variants include Akira v2 and Megazord. Megazord is Rust-based code that appends the .powerranges extension. Lookalikes also exist. ESET found a Babuk-based encryptor that appends .akira and drops a note mimicking Akira’s.
Key Facts at a Glance
| CVE | Product | Issue |
|---|---|---|
| CVE-2024-40766 | SonicWall SonicOS SSL VPN | Improper access control |
| CVE-2023-20269 | Cisco ASA / FTD | Unauthorized VPN access |
| CVE-2020-3259 | Cisco ASA / FTD | Information disclosure |
| CVE-2023-27532 | Veeam Backup & Replication | Credential exposure |
| CVE-2024-37085 | VMware ESXi | Authentication bypass |
Who Is Behind Akira Ransomware? Origin and Attribution
No government has publicly pinned Akira on a named individual or confirmed a country of origin. Evidence points to a code and tradecraft link to the defunct Conti group. Akira actors are associated with Storm-1567, Howling Scorpius, Punk Spider, Gold Sahara, and Conti.
Group Origin and Country-of-Origin Claims
Akira appeared in March 2023 with a polished leak site and a retro-styled negotiation portal on Tor. Anyone claiming a definitive country of origin goes beyond what has been published.
Is Akira Russian? Evidence and Limits of Attribution
Many analysts assume Akira’s operators are Russian-speaking, mostly because of the Conti lineage and the group’s avoidance of certain regions. Neither point proves anything about where the operators sit today. Treat “Russia” as a working assumption, not a finding.
Links to Conti and Other Predecessors
Akira is believed to share code lineage with Conti. Conti disbanded in 2022 and its members scattered into other crews. The overlap suggests Akira was built by people who knew Conti’s playbook.
How the Akira Affiliate Ecosystem Works
Operators handle the encryptors, the leak site, and the Tor negotiation portal. Affiliates buy or exploit access and run the intrusion. Because different affiliates use different tools, shared fingerprints include the VPN-first entry, attack speed, and targeting of backups and hypervisors.
Akira Ransomware Timeline: 2023 to 2026
Akira has expanded every year since 2023, moving from a Windows-only encryptor to a multi-platform operation that is still among the most active groups in 2026. It was still active as of August 26, 2026, with Akira v2 as the current variant and its Tor leak site online.

2023–2024: Emergence and Early Campaigns
Akira launched in March 2023 and first hit Windows systems. From August 2023, some attacks deployed the Rust-based Megazord. As of January 1, 2024, the FBI and CISA counted over 250 impacted organizations and about $42 million in proceeds.
2025: Escalation and CISA/FBI Updates
On April 26, 2025, Hitachi Vantara disclosed a ransomware attack that forced it to take systems offline; Akira claimed it on its leak site. In June 2025, Akira encrypted Nutanix AHV VM disk files for the first time. From July 2025, it exploited SonicWall SSL VPNs. The joint advisory was updated in November, and the proceeds total rose more than fivefold from the 2024 figure.
2026: Developments and Notable Incidents
Akira posted 84 victims in March 2026, more than double February and its second busiest month on record. In August 2026, Huntress documented an intrusion that began, as most Akira incidents do, with a SonicWall SSL VPN. The group also continued to list new victims through September and October.
Latest Akira Ransomware News
On October 2, 2026, Akira claimed an attack on Pacific Tank Lines, a US petroleum carrier, and threatened to leak 13GB of data. Leak-site claims are the group’s own statements and are not independently confirmed.
Who Does Akira Target? Victims and Sectors
Akira most often targets small and mid-sized businesses, and larger organizations when it can access them. Manufacturing, professional services, financial services, and technology are its main sectors, and the US absorbs about half of attacks.
Most-Targeted Industries and Regions
Beyond those four sectors, officials noted a rise in construction targeting in late 2025. North America, Europe, and Australia see the heaviest activity.
Energy Sector and Critical Infrastructure Risk
The updated advisory describes Akira activity as an imminent threat to critical infrastructure. Energy and fuel-logistics companies are exposed in the usual ways: remote-access appliances, backup servers, and virtualization hosts. The Pacific Tank Lines claim shows that fuel transport is on the group’s radar.
Akira Ransomware Victims List and Leak Site Trends
Leak-site tallies are useful for tracking tempo but unreliable as exact counts. The largest victim counts come from the group’s own postings. Halcyon’s April 2026 research put the group’s total at over 1,400 claimed victims since 2023.
Notable Victims by Year
In 2025, Hitachi Vantara was among the best-known disclosed victims. Singapore-based Toppan Next Tech reported an intrusion that exposed client statements. In 2026, claims included RJS Corporation on January 7 and Manders on September 16.
How Akira Ransomware Works: Attack Chain
Akira intrusions typically follow one pattern: gain access through a remote-access path, take over privileged accounts, steal data, turn off defenses, and then encrypt. Halcyon found the group can move from initial access to full network encryption in under four hours.

Initial Access via VPNs and Stolen Credentials
Akira typically gets in through compromised VPN credentials, exploited edge-device vulnerabilities, or credentials bought from initial access brokers. VPN appliances without strong MFA are the most common entry point.
Persistence, Privilege Escalation, and Lateral Movement
Akira creates new local accounts for persistence and relies on Mimikatz, LaZagne, and Rubeus for credential theft. It targets domain controllers, backup servers, and hypervisors because controlling those systems enables mass encryption.
Defense Evasion: How Akira Bypasses Microsoft Defender and EDR
Akira does not bypass Defender through a magic exploit. It gains administrative rights, then switches security tools off, often through vulnerable drivers. In one August 2026 case, an affiliate rebooted a host into Safe Mode to kill security tools, which also broke their own encryptor. Tamper protection and driver blocklists directly counter this.
Data Exfiltration Tools and Techniques
In the same Huntress case, the affiliate archived file shares with WinRAR and sent the data to cloud storage with s5cmd. Staging data in archives and sending it to cloud storage makes egress monitoring worthwhile.
Encryption: File Extensions, Ransom Note, and Windows/Linux Variants
Files are encrypted with ChaCha20, with keys protected by RSA-4096. Encrypted files carry the .akira extension, or .powerranges for Megazord. Since a lookalike also appends .akira, confirm with the ransom note, binaries, and tooling before concluding it is Akira. Akira does not leave an initial ransom demand and negotiates only through its Tor portal.
Akira Targeting VMware and ESXi
Akira ships a dedicated Linux/ESXi encryptor so that a single hypervisor compromise can take down dozens of virtual machines at once. Defenders should patch ESXi, isolate management interfaces, and keep backups the hypervisor cannot reach.
Akira Ransomware and VPN Vulnerabilities
Akira’s most reliable way in is the VPN appliance. SonicWall, Cisco, and similar devices give it a direct path past the perimeter, especially when credentials are old, reused, or protected by weak MFA.
SonicWall CVE-2024-40766 Explained
CVE-2024-40766 is an improper access control flaw in SonicWall SSL VPN. SonicWall patched it in August 2024 and disclosed it in September 2024. The danger came from credentials stolen before patching, which kept working afterward.
SonicWall SSL VPN MFA Bypass: What Happened and Why It Matters
Since July 2025, Akira has logged into SonicWall SSL VPNs even on accounts with one-time-password MFA, likely using stolen OTP seeds; over half of intrusions involved such accounts. Attackers began scanning internal networks within five minutes of logging in. Arctic Wolf saw no compromise of accounts using SSO/SAML for VPN authentication. The lesson is that MFA only protects you if the secrets behind it were never exposed.
Cisco ASA and Cisco VPN Exploitation
CISA’s advisory lists Cisco ASA and FTD flaws among the vulnerabilities used for access, particularly on devices lacking MFA. Patching and enforcing MFA on every Cisco remote-access profile closes most of this exposure.
Fortinet and Other Edge Device Risks
Akira operators probe edge devices from several vendors, Fortinet included. The practical rule is to treat any internet-facing VPN, firewall, or backup product as a priority-one patching target and check it against CISA’s Known Exploited Vulnerabilities catalog.
Akira-Related CVEs Quick-Reference Table
| CVE | Product | Issue |
|---|---|---|
| CVE-2024-40766 | SonicWall SonicOS SSL VPN | Improper access control |
| CVE-2023-20269 | Cisco ASA / FTD | Unauthorized VPN access |
| CVE-2020-3259 | Cisco ASA / FTD | Information disclosure |
| CVE-2023-27532 | Veeam Backup & Replication | Credential exposure |
| CVE-2024-37085 | VMware ESXi | Authentication bypass |
Akira Ransomware TTPs Mapped to MITRE ATT&CK
Akira’s tactics, techniques, and procedures (TTPs) span the full ATT&CK chain, with the densest activity in credential access, defense evasion, and impact. The mapping below helps defenders write detections for each stage.
Full MITRE ATT&CK Mapping Table by Tactic
| Tactic | Technique | ID |
|---|---|---|
| Initial Access | Valid Accounts | T1078 |
| Initial Access | External Remote Services | T1133 |
| Initial Access | Exploit Public-Facing Application | T1190 |
| Persistence | Create Account: Local Account | T1136.001 |
| Credential Access | OS Credential Dumping: LSASS Memory | T1003.001 |
| Credential Access | OS Credential Dumping: NTDS | T1003.003 |
| Defense Evasion | Impair Defenses: Disable or Modify Tools | T1562.001 |
| Discovery | Remote System Discovery | T1018 |
| Lateral Movement | Remote Services: Remote Desktop Protocol | T1021.001 |
| Exfiltration | Exfiltration to Cloud Storage | T1567.002 |
| Impact | Data Encrypted for Impact | T1486 |
| Impact | Inhibit System Recovery | T1490 |
Initial Access, Execution, and Persistence Techniques
Entry almost always occurs through valid accounts or an exposed remote service. Persistence then comes from new local accounts and legitimate remote-access software, which blends in with normal IT activity.
Credential Access, Discovery, and Lateral Movement
Documented behavior includes dumping LSASS via comsvcs.dll and capturing NTDS.dit with ntdsutil. Discovery then relies on built-in Windows tools, and movement happens over RDP and similar services.
Exfiltration and Impact
Data leaves through archive-and-upload workflows. Impact comes with deleted shadow copies and encrypted file servers and hypervisors, so detections should watch for backup tampering before encryption starts.
CISA and FBI Advisories on Akira
The central document is CISA advisory AA24-109A, first published in April 2024. On November 13, 2025, CISA, the FBI, DC3, HHS, Europol, and French, German, and Dutch agencies released an update with expanded TTPs and IOCs. It remains the authoritative reference.
CISA AA24-109A and the November 2025 Update
The update added newer behavior, such as Nutanix AHV encryption, and refreshed indicators. Teams should use the advisory’s IOC list as a starting point for hunting.
FBI Top Five Ransomware Variant Reporting
The FBI reports Akira as one of the top five ransomware variants targeting US businesses, out of more than 130 active groups under investigation.
Guidance for Energy and Critical Infrastructure
Operators in energy and other critical sectors should apply the advisory’s controls first to remote-access appliances, backup systems, and hypervisors. Those are the three places where Akira’s chain most often succeeds.
Official Mitigation Recommendations Summarized
The advisory’s core guidance is to patch known exploited vulnerabilities, enforce phishing-resistant MFA, segment networks, keep offline and tested backups, and monitor for the credential-theft and security-tool-disabling behaviors described above.
Akira Ransomware Indicators of Compromise (IOCs) and Detection
Akira is most detectable between initial persistence and the point where it turns off security tools. That window sits before the vulnerable-driver phase, so alerts on new accounts and credential dumping have the highest value.
File Hashes, Extensions, and Ransom Note Artifacts
Look for the .akira and .powerranges extensions, a ransom note named akira_readme.txt, and executables such as w.exe. Pull current SHA-256 hashes from the November 2025 advisory rather than older lists, since encryptors change between releases.
Network and Behavioral Indicators
Watch for VPN logins from hosting or VPS networks, rapid internal scanning right after a login, and large outbound transfers to cloud storage. Arctic Wolf found Akira SSL VPN logins coming from VPS providers rather than typical broadband networks.
Detection Rules and Threat-Hunting Queries
Prioritize detections for LSASS access via comsvcs.dll, ntdsutil snapshots, new local accounts, security-tool tampering, and shadow-copy deletion. Map each to the ATT&CK table above.
Public Resources
Useful sources include the CISA advisory, SOC Prime and SafeBreach detection content based on it, Trend Micro and Darktrace technical write-ups, and vendor incident reports such as Huntress and Arctic Wolf. Verify any community-posted IOC lists against the advisory.
How to Protect Against Akira Ransomware
The most effective protection is hardening remote access, because that is where Akira gets in. Patch VPNs and firewalls quickly, rotate credentials on any device that ever ran vulnerable firmware, and move to SSO or phishing-resistant MFA.

Patch and Harden VPNs and Edge Devices
Patch within days, not weeks, for anything on CISA’s KEV list. Arctic Wolf’s top mitigation was resetting all SSL VPN credentials on SonicWall devices that ever ran vulnerable firmware, plus the related Active Directory accounts.
Enforce Phishing-Resistant MFA and Credential Hygiene
Replace OTP-only MFA with SSO/SAML or hardware-backed methods where possible, and remove unused or sync-only accounts from VPN access.
Network Segmentation and Backup Strategy
Keep domain controllers, backup servers, and hypervisor management on separate, tightly controlled segments. Maintain offline or immutable backups and test restores regularly.
Protect VMware and ESXi Environments
Patch ESXi, turn off unneeded services, restrict management access, and avoid joining hypervisors to the same domain as general workstations where practical.
Monitor for Leaked Credentials and Dark Web Exposure
Because Akira buys and reuses credentials, monitoring for leaked VPN and employee logins on dark web sources gives you a chance to rotate them before they are used. Pair this with alerts on unusual VPN logins.
Akira Ransomware Infection: Removal, Decryption, and Recovery
If you suspect an Akira infection, isolate affected systems immediately and preserve evidence before rebuilding. Recovery usually depends on clean backups, not on decryption.
First Response Steps Within the First Hour
Quarantine the affected host, capture memory and disk images, and preserve all indicators of compromise. Then deactivate compromised accounts, block the entry path, and bring in an incident-response team.
How to Remove Akira Ransomware Safely
Deleting the encryptor does not remove the intruder. Eradication means rebuilding from known-good images, resetting every credential, and closing the VPN or edge-device path that was used.
Is There an Akira Ransomware Decryptor?
Free decryption exists only for superseded variants, and the Linux method published in March 2025 no longer works on the current version. Avast’s decryptor addressed an early variant and should not be assumed to work today. Check with your incident-response provider before relying on any decryptor.
Recovering Files Without Paying: Backups and Forensics
Restore from offline or immutable backups after confirming the environment is clean. Forensics should determine what data was stolen, since that drives notification duties even if you recover the files.
Akira Ransomware Negotiation: Facts, Risks, and Legal Considerations
Akira communicates only through its Tor-based negotiation portal. Paying does not guarantee a working decryptor or deletion of stolen data, and payments can raise sanctions and legal issues. Involve legal counsel and your insurer before any contact.
Reporting to CISA, FBI, and Regulators
CISA can be reached at contact@cisa.dhs.gov or 1-844-Say-CISA (1-844-729-2472). Report to the FBI as well, and check breach-notification obligations in every jurisdiction where affected people live.
What the Community Is Saying: Reddit and Social Discussion
IT and security forums are a fast source of practical detail, but they are unverified. Threads typically cover SonicWall patching confusion, whether MFA was bypassed, and how to recover without paying.
Common Questions From IT and Security Communities
Frequent questions include whether a patched firewall can still be a risk, whether a decryptor exists, and how to tell Akira from lookalikes.
Real-World Incident Lessons Shared Publicly
Public post-mortems consistently stress credential resets after patching, isolated backups, and early EDR tamper protection. Cross-check any claim against vendor reports or the CISA advisory.
Key Takeaways and Next Steps
Akira ransomware succeeds mainly through remote-access weaknesses, not novel malware. Secure the VPN, rotate credentials after patching, harden backups and hypervisors, and rehearse your response before an incident.
Executive Summary Checklist
Confirm all VPN and edge devices are patched. Reset credentials on any device that ever ran vulnerable firmware. Move off OTP-only MFA. Keep tested offline backups. Segment backup and hypervisor networks.
Defender Action Plan
In the next 30 days, audit remote access, hunt for the IOCs and behaviors listed above, and run a ransomware tabletop exercise with legal and communications teams.
Frequently Asked Questions (FAQ)
What is Akira ransomware?
It is a ransomware-as-a-service operation active since March 2023 that steals data and encrypts systems on Windows, Linux, and virtualization platforms.
Who is behind Akira ransomware?
No individuals have been publicly named. The group is linked by code and tradecraft to the defunct Conti operation.
Is Akira ransomware still active in 2026?
Yes. It was still operating as of late August 2026 and claimed new victims into October.
How does Akira bypass MFA on SonicWall VPNs?
Researchers believe it uses credentials and OTP seeds stolen earlier through CVE-2024-40766, which lets it generate valid codes even after patching. Resetting credentials is the key fix.
Can Akira-encrypted files be decrypted?
Only for older variants, and those tools generally do not work on the current version. Backups are the realistic route.
What file extension does Akira use?
Mainly .akira and .powerranges for Megazord. Lookalike ransomware can use the same extension.
Which industries does Akira target most?
Manufacturing, professional services, financial services, and technology, with growing activity against construction and critical infrastructure.
How much ransom does Akira demand?
Demands reportedly range from about $200,000 to several million dollars.
How can I tell if I’m affected by Akira?
Look for the ransom note, the .akira extension, odd VPN logins from hosting networks, new local accounts, and security tools disabled without explanation.


