All threat actorsAlert me
Akira
Akira is a ransomware variant and deployment entity active since at least March 2023. It uses compromised credentials to access single-factor external access mechanisms like VPNs for initial access, followed by publicly available tools for lateral movement. Akira operations are linked to double extortion tactics, where data is exfiltrated before encryption, with threats to publish files if ransom demands are unpaid. Technical analysis shows overlaps with Conti ransomware and capabilities targeting Windows and VMWare ESXi hypervisors.
Also known as
Akira ransomware
GOLD SAHARA
Howling Scorpius
PUNK SPIDER
REDBIKE
REDBIKE (aka Akira)
REDBIKE (Akira)
Create a free account to see the reports
Sign in or create a free account to see every report that names Akira.
Create free account