Executive Summary
Akira is a rapidly evolving ransomware-as-a-service operation using hybrid AES‑RSA encryption and multi-threading to speed up data lockout. It targets Windows and VMware ESXi environments in high‑profile sectors like manufacturing and education, demanding payments of $6,500–$10,000 for decryption. Organizations should prepare defensive measures even though the malware’s persistence details remain unclear.
Enhanced Description
Akira is a modern ransomware family that originated in C++ and later saw iterations written in Rust, such as the Megazord variant tailored for Windows environments and an Akira v2 version targeted at VMware ESXi hosts. The malware is distributed mainly through subscription‑based ransomware‑as‑a‑service (RaaS) platforms operated by a group identified as Akira. Once executed on victim systems—whether consumer or enterprise—it scans for valuable data assets before encrypting them with a dual‑layer scheme: an initial symmetric AES encryption followed by key encapsulation via RSA to accelerate throughput. The codebase employs multi‑threading and accepts runtime arguments, enabling attackers to customize the payload’s reach and behavior on individual campaigns. In operational use, Akira has been linked to ransomware attacks across North America, Europe, and Australia, targeting critical infrastructure sectors such as manufacturing, education, and IT services. The hybrid encryption strategy coupled with dynamic command‑line parameters considerably shortens the attack window and improves stealth by circumventing basic antivirus heuristics. After encryption, victims receive a ransom note that requests payment in cryptocurrency and typically demands a fee ranging between $6,500–$10,000 for the decryption key. While no evidence of data exfiltration has been observed to date, Akira’s RaaS model implies a potential for monetization through sale or resale of stolen credentials and system information. Overall, Akira represents a sophisticated threat that blends fast encryption performance with flexible delivery mechanisms, posing significant risk to organizations that maintain critical operational assets across multiple geographic regions.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on publicly cited sources (Kersten 2023, CISA April 2024, Cisco October 2024) but lacks deeper technical details such as persistence mechanisms, command‑and‑control infrastructure, or payload delivery vectors. Consequently, confidence in the overall threat picture is moderate; further internal code analysis and network forensics would improve certainty.
Akira ransomware, written in C++, is most prominently (but not exclusively) associated with the ransomware-as-a-service entity Akira. Akira ransomware has been used in attacks across North America, Europe, and Australia, with a focus on critical infrastructure sectors including manufacturing, education, and IT services. Akira ransomware employs hybrid encryption and threading to increase the speed and efficiency of encryption and runtime arguments for tailored attacks. Notable variants include Rust-based Megazord for targeting Windows and Akira _v2 for targeting VMware ESXi servers.(Citation: Kersten Akira 2023)(Citation: CISA Akira Ransomware APR 2024)(Citation: Cisco Akira Ransomware OCT 2024)