← Threat Actors / Global / Akira
DOSSIER // AKIRA

Akira

▲ High Threat
Primary Aliases: PUNK SPIDER Darter G1024 GOLD SAHARA
Sponsor / State Affiliation Independent / Not Attributed
Primary Motivation Espionage / Financial
Active Timeline Unknown – Present
Confidence Rating 80% (Grounded)

Akira is a ransomware variant and ransomware deployment entity active since at least March 2023.(Citation: Arctic Wolf Akira 2023) Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement.(Citation: Arctic Wolf Akira 2023)(Citation: Secureworks GOLD SAHARA) Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.(Citation: BushidoToken Akira 2023)(Citation: CISA Akira Ransomware APR 2024)(Citation: Cisco Akira Ransomware OCT 2024)

⚔️ Weaponized CVE Matrix (1)

🎯 Target Sectors & Focus

Defense & Aerospace Government & Diplomacy Financial & Crypto Critical Infrastructure
Copied to clipboard

LINK COPIED TO CLIPBOARD