Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: GOLD SAHARA, PUNK SPIDER, Howling Scorpius
17
techniques
8
software
9,936
corpus matches
profile
Akira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.
techniques
17 attributed · most-instrumented first
software
8 malware & tools attributed
Mimikatz
S0002
PsExec
S0029
LaZagne
S0349
AdFind
S0552
Rclone
S1040
Akira
S1129
Megazord
S1191
Akira _v2
S1194
read this carefully
9,936 corpus matches is not attribution
That count is indicators which exhibit techniques Akira is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
collection
+5 more techniques
showing 30 of 9,936
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.