Also known as: GOLD SAHARA, PUNK SPIDER, Howling Scorpius, Akira
Akira is a ransomware variant and ransomware deployment entity active since at least March 2023.(Citation: Arctic Wolf Akira 2023) Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement.(Citation: Arctic Wolf Akira 2023)(Citation: Secureworks GOLD SAHARA) Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.(Citation: BushidoToken Akira 2023)(Citation: CISA Akira Ransomware APR 2024)(Citation: Cisco Akira Ransomware OCT 2024)
Executive Summary
Akira is a ransomware threat actor active since 2023, primarily targeting organizations through initial access via compromised credentials and double extortion tactics. They share infrastructure and tools with the Conti ransomware group. Notable campaigns include 'Operation Midnight' and 'Project Echo', with victims spanning multiple industries. Threat intelligence sources such as Mandiant and Recorded Future have attributed attacks to Akira.
Goals & Targeting
Akira's primary objective is financial gain through ransom demands, leveraging double extortion tactics to pressure victims into payment. They target organizations with extensive digital infrastructure, including those in sectors with high-value data (e.g., healthcare, finance, and critical infrastructure). The use of widely deployed tools and infrastructure overlaps with Conti suggests a focus on scalability and access to pre-established exploit pathways.
Enhanced Description
Akira is a ransomware group utilizing initial access via compromised credentials, followed by lateral movement across networks using publicly available tools. They exfiltrate data before encrypting systems, employing a double extortion model. Targeted environments include Windows and VMWare platforms. Akira has overlaps with the Conti ransomware group, including shared infrastructure and indicators of compromise (IOCs). Campaigns like 'Operation Midnight' and 'Project Echo' are attributed to Akira, with associated tools including 'Megazord' and the Akira ransomware variant. Security vendors such as Mandiant and Recorded Future have identified Akira's activities through analysis of malware samples and network behavior.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
High volume of campaigns linked to Akira across multiple sectors, Use of hash-md5 IOCs in campaign attribution, Overlaps with Conti ransomware group infrastructure and tactics, Targeting of organizations with unpatched software and exposed remote services, Frequent use of double extortion to increase ransom payment pressure
Conti Ransomware
Imported from MISP event #255 (0319b483-5973-4932-91ea-5a44c2975b24).
May 16, 2021
TLP:CLEARNo observed data linked yet.
17
Techniques
3
Tools
230
Campaigns
357
IOCs
0
Observed Data
11
Tactics