Akira

G1024

Threat group.View on attack.mitre.org

About this group

Akira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.

Techniques used17

Procedure examples17

TechniqueProcedure example
T1018
Remote System Discovery

Akira uses software such as Advanced IP Scanner and MASSCAN to identify remote hosts within victim networks.

T1021.001
Remote Desktop Protocol

Akira has used RDP for lateral movement.

T1027.001
Binary Padding

Akira has used binary padding to obfuscate payloads.

T1036.005
Match Legitimate Resource Name or Location

Akira has used legitimate names and locations for files to evade defenses.

T1059.001
PowerShell

Akira has used PowerShell scripts for credential harvesting and privilege escalation.

T1078
Valid Accounts

Akira uses valid account information to remotely access victim networks, such as VPN credentials.

T1133
External Remote Services

Akira uses compromised VPN accounts for initial access to victim networks.

T1213.002
Sharepoint

Akira has accessed and downloaded information stored in SharePoint instances as part of data gathering and exfiltration activity.

T1219
Remote Access Tools

Akira uses legitimate utilities such as AnyDesk and PuTTy for maintaining remote access to victim environments.

T1482
Domain Trust Discovery

Akira uses the built-in Nltest utility or tools such as AdFind to enumerate Active Directory trusts in victim environments.

T1486
Data Encrypted for Impact

Akira encrypts files in victim environments as part of ransomware operations.

T1531
Account Access Removal

Akira deletes administrator accounts in victim networks prior to encryption.

T1558
Steal or Forge Kerberos Tickets

Akira have used scripts to dump Kerberos authentication credentials.

T1560.001
Archive via Utility

Akira uses utilities such as WinRAR to archive data prior to exfiltration.

T1567.002
Exfiltration to Cloud Storage

Akira will exfiltrate victim data using applications such as Rclone.

View all 17 procedure examples

Software8

Campaigns0

None recorded.

References5

  1. Arctic Wolf Akira 2023 Open source
    Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.
  2. BushidoToken Akira 2023 Open source
    Will Thomas. (2023, September 15). Tracking Adversaries: Akira, another descendent of Conti. Retrieved February 21, 2024.
  3. CISA Akira Ransomware APR 2024 Open source
    CISA et al. (2024, April 18). #StopRansomware: Akira Ransomware. Retrieved December 10, 2024.
  4. Cisco Akira Ransomware OCT 2024 Open source
    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.
  5. Secureworks GOLD SAHARA Open source
    Secureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.