Akira
Medium ConfidenceHigh ThreatStorm-1567
Akira is a ransomware operation that emerged in March 2023, targeting small to medium-sized businesses across various sectors. The group is believed to have connections to the disbanded Conti ransomware operation. Akira employs double extortion tactics and has targeted organizations in North America, Europe, and Australia. The group is known for exploiting VPN vulnerabilities for initial access and using legitimate tools for network reconnaissance.
Akira is a ransomware operation that emerged in March 2023, targeting small to medium-sized businesses across various sectors. The group is believed to have connections to the disbanded Conti ransomware operation. Akira employs double extortion tactics and has targeted organizations in North America, Europe, and Australia. The group is known for exploiting VPN vulnerabilities for initial access and using legitimate tools for network reconnaissance.
Target Sectors
Target Regions
Attributed to Cybercriminal (No State Sponsor) (Russia). Attribution confidence: Medium.
Future Outlook
Akira is expected to continue operations targeting Manufacturing sectors.
First observed activity of Akira
Continued active operations