Akira
Ransomware-as-a-Service (RaaS) operation (Eastern Europe assessed) · Financial — ransomware and double extortion
Tactics, Techniques & Procedures (TTPs)
- VPN credential compromise as primary initial access vector — Cisco ASA, SonicWall, and FortiGate appliances exploited within days of CVE disclosure
- ESXi-specific encryptor: targets VMware ESXi hosts via ChaCha20 encryption of VMDK files, with simultaneous Windows encryptor for hybrid environments
- Hyper-V targeting with NVMe-AIO (NVMe Asynchronous I/O) technique for high-speed encryption bypassing standard file I/O rates
- Double-extortion model: data exfiltration via Rclone to attacker-controlled cloud storage followed by encryption deployment
- Credential harvesting using Mimikatz, LSASS dump, and Windows Credential Manager extraction
- Lateral movement via RDP and PsExec following Active Directory enumeration (SharpHound/BloodHound)
- Short negotiation windows and aggressive leak site — publishes victim data faster than most RaaS operations
Known Targets
Analyst Notes
Akira emerged March 2023 and reached $244M+ in confirmed ransom payments by mid-2025 across 300+ victims (FBI/CISA AA24-109A). The group systematically targets organisations with exposed VPN appliances, moving to ESXi infrastructure once inside to maximise encryption impact per intrusion. The NVMe-AIO encryption technique — exploiting high-throughput NVMe I/O to encrypt at speeds faster than backup solutions can detect and block — represents genuine capability investment. Akira affiliates have been documented selling access to initial compromises before encryption, overlapping with the access broker ecosystem. KongTuke, a documented IAB, has sold footholds to Akira affiliates.
Also Known As