Skip to content
The Nexus
Group profile37 claimed in last 30d165 total tracked

akira

Forward this

The Akira ransomware group is said to have emerged in March 2023, and there's much speculation about its ties to the former CONTI ransomware group. It's worth noting that with the end of CONTI's operation, several affiliates migrated to independent campaigns such as Royal, BlackBasta, and others. According to some reports, Akira affiliates also work with other ransomware operations, such as Snatch and BlackByte, as an open directory of tools used by an Akira operator was identified, which also had connections to the Snatch ransomware. The first version of the Akira ransomware was written in C++ and appended files with the '.akira' extension, creating a ransom note named 'akira_readme.txt,' partially based on the Conti V2 source code. However, on June 29, 2023, a decryptor for this version was reportedly released by Avast. Subsequently, a version was released that fixed the decryption flaw on July 2, 2023. Since then, the new version is said to be written in Rust, this time called 'megazord.exe,' and it changes the extension to '.powerranges' for encrypted files. Most of Akira's initial access vectors use brute-force attempts on Cisco VPN devices (which use single-factor authentication only). Additionally, exploitation of CVEs: CVE-2019-6693 and CVE-2022-40684 for initial access has been identified. Source: https://github.com/crocodyli/ThreatActors-TTPs

First seen: May 18 · 00:00 UTCLast seen: Aug 24 · 00:00 UTCTracked since: 2023-04-26
Sectors hit
  • Manufacturing18
  • Business Services16
  • Unspecified8
  • Consumer Services8
  • Hospitality and Tourism7
  • Retail & E-Commerce5
  • Financial Services5
  • Technology4
Countries hit
  • United States33
  • United Kingdom4
  • Germany3
  • Canada2
  • NJ1
  • Japan1
  • Italy1
  • Spain1
  • Czechia1
  • Switzerland1
MITRE ATT&CK · observed TTPs14 tactics

Tactics and techniques attributed to AKIRA by ransomware.live's curated TTP catalog. Identifiers link to the canonical MITRE ATT&CK reference for each tactic or sub-technique.

  • TA0001Initial Access
    • T1078Valid Accounts

      Utilizes compromised VPN credentials.

    • T1078.002Valid Accounts: Domain Accounts

      Operators use obtained domain accounts for access.

    • T1133External Remote Services

      Actors exploit CVE-2023-20269 remote service vulnerabilities.

    • T1190Exploit Public-Facing Application

      Targets vulnerable CISCO devices via CVE-2023-20269.

  • TA0002Execution
    • T1047Windows Management Instrumentation

      Actors may use WMI to continue the attack.

    • T1059Command and Scripting Interpreter

      Accepts parameters for its routines such as "-n 10" (for encryption percentage) or "-s (filename)" (for shared folder encryption).

    • T1059.001Command and Scripting Interpreter: PowerShell

      Operators use PowerShell to launch commands to continue operations.

    • T1059.002System Services: Service Execution

      Akira ransomware uses service execution for persistence.

    • T1059.003Command and Scripting Interpreter: Windows Command Shell

      Operators use CMD to launch commands to continue operations.

  • TA0003Persistence
    • T1136.001Create Account: Local Account

      Upon initial access, Akira operators create a local account on the compromised system.

    • T1136.002Create Account: Domain Account

      Upon initial access, Akira operators create a domain account on the compromised system.

  • TA0004Privilege Escalation
    • T1078.002Valid Accounts: Domain Accounts

      Utilizes valid domain accounts for privilege escalation.

    • TA0004Privilege Escalation

      Utilizes local domain accounts for privilege escalation.

  • TA0005Stealth
    • T1027.001Obfuscated Files or Information: Binary Padding

      [Akira](https://attack.mitre.org/groups/G1024) has used binary padding to obfuscate payloads.(Citation: Cisco Akira Ransomware OCT 2024)

    • T1036.005Masquerading: Match Legitimate Resource Name or Location

      [Akira](https://attack.mitre.org/groups/G1024) has used legitimate names and locations for files to evade defenses.(Citation: Cisco Akira Ransomware OCT 2024)

  • TA0005Defense Evasion
    • T1112Modify Registry

      Uses commands in its operation to modify registries.

    • T1562.001Impair Defenses: Disable or Modify Tools

      Usage of PowerTool or a KillAV tool abusing the Zemana AntiMalware driver to terminate AV-related processes was observed.

  • TA0006Credential Access
    • T1003.001OS Credential Dumping: LSASS Memory

      Uses Mimikatz, LaZagne, or a command line to dump LSASS from memory.

    • T1558Steal or Forge Kerberos Tickets

      [Akira](https://attack.mitre.org/groups/G1024) have used scripts to dump Kerberos authentication credentials.(Citation: Cisco Akira Ransomware OCT 2024)

  • TA0007Discovery
    • T1018Remote System Discovery

      Uses Advanced IP Scanner and MASSCAN to discover remote systems.

    • T1082System Information Discovery

      Uses PCHunter and SharpHound to collect system information.

    • T1482Domain Trust Discovery

      [Akira](https://attack.mitre.org/groups/G1024) uses the built-in [Nltest](https://attack.mitre.org/software/S0359) utility or tools such as [AdFind](https://attack.mitre.org/software/S0552) to enumerate Active Directory trusts in victim environments.(Citation: Arctic Wolf Akira 2023)

    • TA0007Discovery

      Uses AdFind, Windows net command, and nltest to collect domain information.

  • TA0008Lateral Movement
    • T1021.001Remote Services: Remote Desktop Protocol

      Utilizes remote services for accessing accounts and machines through remote services.

    • T1570Lateral Tool Transfer

      Uses RDP to move laterally within the victim's network.

  • TA0009Collection
    • T1213.002Data from Information Repositories: Sharepoint

      [Akira](https://attack.mitre.org/groups/G1024) has accessed and downloaded information stored in SharePoint instances as part of data gathering and exfiltration activity.(Citation: Secureworks GOLD SAHARA)

    • T1560.001Archive Collected Data: Archive via Utility

      Utilizes discovery to gather information for exfiltration.

  • TA0010Exfiltration
    • T1048.003Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol

      Utilizes FileZilla or WinSCP to exfiltrate stolen information via FTP.

    • T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage

      Uses RClone to exfiltrate stolen information via a web service.

  • TA0011Command and Control
    • T1219Remote Access Tools

      [Akira](https://attack.mitre.org/groups/G1024) uses legitimate utilities such as AnyDesk and PuTTy for maintaining remote access to victim environments.(Citation: Secureworks GOLD SAHARA)(Citation: Arctic Wolf Akira 2023)

    • T1229Remote Access Software

      Utilizes AnyDesk, Radmin, Cloudflare Tunnel, MobaXterm, RustDesk, or Ngrok to gain remote access on targeted systems.

  • TA0040Impact
    • T1486Data Encrypted for Impact

      Akira ransomware is used to encrypt files.

    • T1490Inhibit System Recovery

      Deletes shadow copies to inhibit recovery.

    • T1531Account Access Removal

      [Akira](https://attack.mitre.org/groups/G1024) deletes administrator accounts in victim networks prior to encryption.(Citation: Secureworks GOLD SAHARA)

    • T1657Financial Theft

      [Akira](https://attack.mitre.org/groups/G1024) engages in double-extortion ransomware, exfiltrating files then encrypting them, in order to prompt victims to pay a ransom.(Citation: BushidoToken Akira 2023)(Citation: CISA Akira Ransomware APR 2024)

  • TA0112Defense Impairment
    • T1685Disable or Modify Tools

      [Akira](https://attack.mitre.org/groups/G1024) has disabled or modified security tools for defense evasion.(Citation: Cisco Akira Ransomware OCT 2024)

Recent claimed victims
Aug 24 · 17:29 UTC

Bihl

Aug 21 · 16:26 UTC

JC Sales

Retail & E-CommerceUnited StatesAug 21 · 13:21 UTC

JC Sales

jcsalesweb.com
Aug 20 · 18:37 UTC

Deas Millwork

Aug 20 · 18:37 UTC

Cascade Coffee

Retail & E-CommerceUnited StatesAug 20 · 14:21 UTC

Cascade Coffee

cascadecoffee.com
ManufacturingAug 20 · 13:51 UTC

Deas Millwork

Aug 19 · 17:43 UTC

Ericksen Krentel

Professional ServicesAug 19 · 15:21 UTC

Ericksen Krentel

ericksenkrentel.com
Aug 18 · 17:43 UTC

Borchert & LaSpina

Aug 14 · 16:29 UTC

Keystops

Aug 14 · 16:29 UTC

Cozad Asset Management

TechnologyUnited StatesAug 14 · 13:52 UTC

Keystops

keystops.com
Financial ServicesUnited StatesAug 14 · 13:51 UTC

Cozad Asset Management

cozadasset.com
Aug 13 · 16:34 UTC

CF Supply

Retail & E-CommerceAug 13 · 13:24 UTC

CF Supply

Aug 10 · 16:31 UTC

One Vision Imaging

Aug 10 · 16:31 UTC

i4 Solutions

Aug 10 · 16:31 UTC

Alcast

ManufacturingAug 10 · 14:21 UTC

Alcast

HealthcareAug 10 · 13:22 UTC

One Vision Imaging

TechnologyAug 10 · 13:22 UTC

i4 Solutions

Aug 6 · 15:52 UTC

Pharma Test Apparatebau AG

Aug 6 · 15:52 UTC

Basic Grain Products

Agriculture and Food ProductionAug 6 · 12:21 UTC

Basic Grain Products

ManufacturingSwitzerlandAug 6 · 11:51 UTC

Pharma Test Apparatebau AG

ManufacturingAug 4 · 12:51 UTC

University SprinklerSystems

Aug 3 · 17:32 UTC

Belasco Electric

Aug 3 · 17:32 UTC

Albers Mechanical Contractors

ManufacturingUnited StatesAug 3 · 12:50 UTC

Albers Mechanical Contractors

albersmechanicalcontractors.com
Energy & UtilitiesUnited StatesAug 3 · 12:21 UTC

Belasco Electric

belascoelectric.com
Jul 29 · 16:54 UTC

Northwood Country Club

HospitalityUnited StatesJul 29 · 13:50 UTC

Northwood Country Club

northwoodcountryclub.org
Jul 28 · 19:00 UTC

Franz Krause artworksgroup

OtherUnited StatesJul 28 · 14:22 UTC

Franz Krause artworksgroup

Jul 24 · 14:49 UTC

Emerge2 Digital

TechnologyCanadaJul 24 · 11:50 UTC

Emerge2 Digital

emerge2.com
Jul 22 · 18:55 UTC

Kruse Construction

Jul 22 · 18:55 UTC

University Sprinkler Systems

ManufacturingJul 22 · 13:53 UTC

Kruse Construction

Professional ServicesCanadaJul 22 · 13:52 UTC

University Sprinkler Systems

Jul 22 · 06:20 UTC

Finer & Finer

Jul 22 · 06:20 UTC

Novasport s.r.o.

Retail & E-CommerceCzechiaJul 21 · 12:53 UTC

Novasport s.r.o.

Retail & E-CommerceUnited StatesJul 21 · 11:53 UTC

Finer & Finer

Jul 20 · 20:56 UTC

McKeever , Varga & Senko

Jul 20 · 20:56 UTC

L&A Transport

Professional ServicesUnited StatesJul 20 · 13:53 UTC

McKeever , Varga & Senko

mvs-cpa.com
TransportationUnited StatesJul 20 · 13:53 UTC

L&A Transport

landatransport.com
Jul 17 · 15:52 UTC

Westcoast Communication Services

Jul 17 · 14:51 UTC

Nesco Bus Maintenance

TelecommunicationUnited StatesJul 17 · 12:51 UTC

Westcoast Communication Services

westcoastcomm.com
Transportation/LogisticsUnited StatesJul 17 · 12:22 UTC

Nesco Bus Maintenance

nescobus.com
Jul 16 · 15:50 UTC

Plumley Engineering

ManufacturingUnited StatesJul 16 · 12:52 UTC

Plumley Engineering

PlumleyEng.com
Jul 15 · 15:53 UTC

Pioneer Construction

ConstructionJul 15 · 13:21 UTC

Pioneer Construction

Jul 13 · 16:52 UTC

Transworld Signs