Skip to content
← All Threat Actors
Cybercrime high Eastern Europe (assessed)

Akira

Ransomware-as-a-Service (RaaS) operation (Eastern Europe assessed) · Financial — ransomware and double extortion

Reports 1
Active Since 2023
Last Reported 16 Jul 2026
Sectors Targeted professional-services, manufacturing, healthcare, education, finance

Tactics, Techniques & Procedures (TTPs)

  • VPN credential compromise as primary initial access vector — Cisco ASA, SonicWall, and FortiGate appliances exploited within days of CVE disclosure
  • ESXi-specific encryptor: targets VMware ESXi hosts via ChaCha20 encryption of VMDK files, with simultaneous Windows encryptor for hybrid environments
  • Hyper-V targeting with NVMe-AIO (NVMe Asynchronous I/O) technique for high-speed encryption bypassing standard file I/O rates
  • Double-extortion model: data exfiltration via Rclone to attacker-controlled cloud storage followed by encryption deployment
  • Credential harvesting using Mimikatz, LSASS dump, and Windows Credential Manager extraction
  • Lateral movement via RDP and PsExec following Active Directory enumeration (SharpHound/BloodHound)
  • Short negotiation windows and aggressive leak site — publishes victim data faster than most RaaS operations

Known Targets

Professional services firmsManufacturing and logisticsHealthcare organisationsEducation sector (universities, school districts)Financial servicesCritical infrastructure operatorsSmall and mid-size businesses across 30+ countries

Analyst Notes

Akira emerged March 2023 and reached $244M+ in confirmed ransom payments by mid-2025 across 300+ victims (FBI/CISA AA24-109A). The group systematically targets organisations with exposed VPN appliances, moving to ESXi infrastructure once inside to maximise encryption impact per intrusion. The NVMe-AIO encryption technique — exploiting high-throughput NVMe I/O to encrypt at speeds faster than backup solutions can detect and block — represents genuine capability investment. Akira affiliates have been documented selling access to initial compromises before encryption, overlapping with the access broker ecosystem. KongTuke, a documented IAB, has sold footholds to Akira affiliates.

Also Known As

No confirmed aliases; Megazord ransomware used in some campaigns alongside Akira encryptor