Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Akira

Akira

TLP:CLEAR
Family

AI Analysis

· 2 days ago

Executive Summary

Akira is a rapidly evolving ransomware-as-a-service operation using hybrid AES‑RSA encryption and multi-threading to speed up data lockout. It targets Windows and VMware ESXi environments in high‑profile sectors like manufacturing and education, demanding payments of $6,500–$10,000 for decryption. Organizations should prepare defensive measures even though the malware’s persistence details remain unclear.

Enhanced Description

Akira is a modern ransomware family that originated in C++ and later saw iterations written in Rust, such as the Megazord variant tailored for Windows environments and an Akira v2 version targeted at VMware ESXi hosts. The malware is distributed mainly through subscription‑based ransomware‑as‑a‑service (RaaS) platforms operated by a group identified as Akira. Once executed on victim systems—whether consumer or enterprise—it scans for valuable data assets before encrypting them with a dual‑layer scheme: an initial symmetric AES encryption followed by key encapsulation via RSA to accelerate throughput. The codebase employs multi‑threading and accepts runtime arguments, enabling attackers to customize the payload’s reach and behavior on individual campaigns. In operational use, Akira has been linked to ransomware attacks across North America, Europe, and Australia, targeting critical infrastructure sectors such as manufacturing, education, and IT services. The hybrid encryption strategy coupled with dynamic command‑line parameters considerably shortens the attack window and improves stealth by circumventing basic antivirus heuristics. After encryption, victims receive a ransom note that requests payment in cryptocurrency and typically demands a fee ranging between $6,500–$10,000 for the decryption key. While no evidence of data exfiltration has been observed to date, Akira’s RaaS model implies a potential for monetization through sale or resale of stolen credentials and system information. Overall, Akira represents a sophisticated threat that blends fast encryption performance with flexible delivery mechanisms, posing significant risk to organizations that maintain critical operational assets across multiple geographic regions.

Key Capabilities

  • Hybrid symmetric/asymmetric encryption (AES + RSA)
  • Multithreaded file‑system traversal for faster data locking
  • Runtime command‑line arguments to customize attacks
  • Ransomware-as-a-Service delivery model
  • Targeting of Windows and VMware ESXi platforms
  • Focus on critical infrastructure in manufacturing, education, and IT services

ATT&CK Techniques

T1486
T1059

Recommended Actions

  • Implement strict application whitelisting and restrict execution rights for unknown binaries
  • Use full‑disk or individual file encryption solutions with regular backups to isolate ransomware impact
  • Apply least‑privilege permissions for account access to mitigate potential credential acquisition
  • Deploy behavioral detection rules that flag sudden, multi‑threaded encryption activity
  • Maintain up-to-date signatures for known Akira families across antivirus platforms
  • Implement network segmentation and monitoring for anomalous outbound traffic from compromised hosts

Suggested Tags

ransomware
Akira
Ransomware-as-a-Service
Windows
VMware-ESXi
Hybrid-Encryption
Multithreaded
Critical-Infrastructure
Manufacturing
Education
IT-Services
Cryptocurrency-Ransom

Confidence Assessment

The analysis is based on publicly cited sources (Kersten 2023, CISA April 2024, Cisco October 2024) but lacks deeper technical details such as persistence mechanisms, command‑and‑control infrastructure, or payload delivery vectors. Consequently, confidence in the overall threat picture is moderate; further internal code analysis and network forensics would improve certainty.

Description

Akira ransomware, written in C++, is most prominently (but not exclusively) associated with the ransomware-as-a-service entity Akira. Akira ransomware has been used in attacks across North America, Europe, and Australia, with a focus on critical infrastructure sectors including manufacturing, education, and IT services. Akira ransomware employs hybrid encryption and threading to increase the speed and efficiency of encryption and runtime arguments for tailored attacks. Notable variants include Rust-based Megazord for targeting Windows and Akira _v2 for targeting VMware ESXi servers.(Citation: Kersten Akira 2023)(Citation: CISA Akira Ransomware APR 2024)(Citation: Cisco Akira Ransomware OCT 2024)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.