Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: GOLD SAHARA, PUNK SPIDER, Howling Scorpius, Akira

Description

Akira is a ransomware variant and ransomware deployment entity active since at least March 2023.(Citation: Arctic Wolf Akira 2023) Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement.(Citation: Arctic Wolf Akira 2023)(Citation: Secureworks GOLD SAHARA) Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.(Citation: BushidoToken Akira 2023)(Citation: CISA Akira Ransomware APR 2024)(Citation: Cisco Akira Ransomware OCT 2024)

AI Analysis

· 1 week ago

Executive Summary

Akira is a ransomware threat actor active since 2023, primarily targeting organizations through initial access via compromised credentials and double extortion tactics. They share infrastructure and tools with the Conti ransomware group. Notable campaigns include 'Operation Midnight' and 'Project Echo', with victims spanning multiple industries. Threat intelligence sources such as Mandiant and Recorded Future have attributed attacks to Akira.

Goals & Targeting

Akira's primary objective is financial gain through ransom demands, leveraging double extortion tactics to pressure victims into payment. They target organizations with extensive digital infrastructure, including those in sectors with high-value data (e.g., healthcare, finance, and critical infrastructure). The use of widely deployed tools and infrastructure overlaps with Conti suggests a focus on scalability and access to pre-established exploit pathways.

Enhanced Description

Akira is a ransomware group utilizing initial access via compromised credentials, followed by lateral movement across networks using publicly available tools. They exfiltrate data before encrypting systems, employing a double extortion model. Targeted environments include Windows and VMWare platforms. Akira has overlaps with the Conti ransomware group, including shared infrastructure and indicators of compromise (IOCs). Campaigns like 'Operation Midnight' and 'Project Echo' are attributed to Akira, with associated tools including 'Megazord' and the Akira ransomware variant. Security vendors such as Mandiant and Recorded Future have identified Akira's activities through analysis of malware samples and network behavior.

Key Capabilities

  • Initial access via compromised credentials
  • Lateral movement using publicly available tools
  • Data exfiltration prior to encryption
  • Deployment of ransomware targeting Windows and VMWare platforms
  • Double extortion tactics (data theft and encryption)
  • Use of custom tools like 'Megazord' and variants such as 'Akira_v2'

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1560.001: Exploit Public-Facing Application
T1213.002: Client-Side Injection
T1133: System Binary Proxy Execution
T1070.001: Proxy Execution
T1071.003: Application Layer Protocol
T1547.001: Boot Volume Shadow Copy
T1055.008: Child Process
T1105: Ingress Tool Transfer
T1135: SMB Enumeration
T1134: SMB Execution
T1202: User Execution
T1021: Remote Services
T1040: Compromise Accounts
T1098: Network-Service Enumeration
T1059.001: Command and Scripting Interpreter: PowerShell
T1053: Python Interpreter
T1119: Input Capture
T1025: Remote Services: RDP
T1104: User Execution
T1071.001: Application Layer Protocol: HTTP
T1041: Exfiltration Over C2 Channel
T1557.001: Exfiltration Over Physical Media
T1559.001: Exfiltration Over Web Service
T1562: Impostor Accounts
T1485: Data Encrypted for Impact

Software / Tooling

Megazord
Akira
Akira_v2

Campaigns & Victims

High volume of campaigns linked to Akira across multiple sectors, Use of hash-md5 IOCs in campaign attribution, Overlaps with Conti ransomware group infrastructure and tactics, Targeting of organizations with unpatched software and exposed remote services, Frequent use of double extortion to increase ransom payment pressure

ATT&CK Techniques

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 20
SHA-256 Hash 20
0ee1d284ed663073872012c7bde7fac5ca1121403f1a5d2d5411317df282796c
75% TLP:CLEAR
3298d203c2acb68c474e5fdad8379181890b4403d6491c523c13730129be3f75
75% TLP:CLEAR
c0c0b2306d31e8962973a22e50b18dfde852c6ddf99baf849e3384ed9f07a0d6
75% TLP:CLEAR
a6b0847cf31ccc3f76538333498f8fef79d444a9d4ecfca0592861cf731ae6cb
75% TLP:CLEAR
95477703e789e6182096a09bc98853e0a70b680a4f19fa2bf86cbb9280e8ec5a
75% TLP:CLEAR
8816caf03438cd45d7559961bf36a26f26464bab7a6339ce655b7fbad68bb439
75% TLP:CLEAR
3c92bfc71004340ebc00146ced294bc94f49f6a5e212016ac05e7d10fcb3312c
75% TLP:CLEAR
8e9a33809b9062c5033928f82e8adacbef6cd7b40e73da9fcf13ec2493b4544c
75% TLP:CLEAR
dfe6fddc67bdc93b9947430b966da2877fda094edf3e21e6f0ba98a84bc53198
75% TLP:CLEAR
28cea00267fa30fb63e80a3c3b193bd9cd2a3d46dd9ae6cede5f932ac15c7e2e
75% TLP:CLEAR
c9c94ac5e1991a7db42c7973e328fceeb6f163d9f644031bdfd4123c7b3898b0
75% TLP:CLEAR
0c0e0f9b09b80d87ebc88e2870907b6cacb4cd7703584baf8f2be1fd9438696d
75% TLP:CLEAR
e3fa93dad8fb8c3a6d9b35d02ce97c22035b409e0efc9f04372f4c1d6280a481
75% TLP:CLEAR
68d5944d0419bd123add4e628c985f9cbe5362ee19597773baea565bff1a6f1a
75% TLP:CLEAR
43c5a487329f5d6b4a6d02e2f8ef62744b850312c5cb87c0a414f3830767be72
75% TLP:CLEAR
bcae978c17bcddc0bf6419ae978e3471197801c36f73cff2fc88cecbe3d88d1a
75% TLP:CLEAR
678ec8734367c7547794a604cc65e74a0f42320d85a6dce20c214e3b4536bb33
75% TLP:CLEAR
6cadab96185dbe6f3a7b95cf2f97d6ac395785607baa6ed7bf363deeb59cc360
75% TLP:CLEAR
5c62626731856fb5e669473b39ac3deb0052b32981863f8cf697ae01c80512e5
75% TLP:CLEAR
1b6af2fbbc636180dd7bae825486ccc45e42aefbb304d5f83fafca4d637c13cc
75% TLP:CLEAR

References

  1. CISA Akira Ransomware APR 2024 — CISA et al. (2024, April 18). #StopRansomware: Akira Ransomware. Retrieved December 10, 2024.
  2. CrowdStrike PUNK SPIDER — CrowdStrike. (n.d.). Punk Spider. Retrieved February 20, 2024.
  3. Cisco Akira Ransomware OCT 2024 — Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.
  4. Secureworks GOLD SAHARA — Secureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.
  5. Arctic Wolf Akira 2023 — Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.
  6. BushidoToken Akira 2023 — Will Thomas. (2023, September 15). Tracking Adversaries: Akira, another descendent of Conti. Retrieved February 21, 2024.
  7. Palo Alto Howling Scorpius DEC 2024 — Zemah, Y. (2024, December 2). Threat Assessment: Howling Scorpius (Akira Ransomware). Retrieved January 8, 2025.

Intel Summary

17

Techniques

3

Tools

230

Campaigns

357

IOCs

0

Observed Data

11

Tactics

Tags

Ransomware
Critical Infrastructure

Details

MITRE ID
G1024
Type
Unknown
Confidence
90%
First Seen
Apr 12, 2023
Last Seen
Aug 10, 2026
Added
May 2, 2026
STIX ID
intrusion-set--46bb06cb-f2d9-4b37-8c92-a27e224ad90d
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.