ZeroHour

akira

ransomware group · aka Akira, Akira_VP (Linux/VMware ESXi variant), HDK / 'How Daemons Kill' (reported rebrand of its Linux encryptor, 2024) · Unknown; believed to be Russian-speaking. Some researchers have speculated links to former Conti-affiliated operators (unconfirmed). · active since March 2023

Victims · 7d
9flat
Victims · 30d
43active targets
Victims · 90d
86
All-time (tracked)
1.5Ksince 2023-04-29
Last post
09-17 17:39UTC
Estimated earnings
Approximately $42 million in ransom proceeds as of March 2024; no comprehensive public estimate since.public reporting
Profile · glm-5.3-flash · updated

Akira is a ransomware and data-extortion group first observed in March 2023, known for double extortion and a dedicated leak site used to pressure non-paying victims. It primarily targets small and mid-sized organizations across multiple sectors in North America and Europe, gaining initial access through SSL VPNs and edge appliances (notably Cisco ASA/FTD and SonicWall) often without multi-factor authentication. The group operates both Windows and Linux/VMware ESXi encryptors (Akira_VP) and, per 2025 vendor reporting, has used Windows Safe Mode reboots and attempted EDR tampering to evade defenses. The FBI and CISA estimated roughly $42 million in ransom proceeds as of March 2024 (source: FBI/CISA joint advisory, 2024). The group remains active, with this dashboard tracking five new leak-site victims in the past seven days (last post 2026-09-09).

Tactics & tooling
  • Initial access via SSL VPNs/edge appliances lacking MFA; exploits Cisco ASA/FTD (CVE-2023-20269) and SonicWall SonicOS (CVE-2024-40766); 2025 reporting also links affiliates to SonicWall SSL VPN zero-day exploitation.
  • Double extortion: data exfiltration followed by encryption; leak-site shaming of non-payers.
  • Dual-platform encryptors: Windows locker plus Linux/VMware ESXi variant (Akira_VP).
  • Exfiltration using cloud storage and transfer tools, including MEGA (MEGAsync) and Rclone, per FBI/CISA reporting.
  • EDR evasion: rebooting hosts into Windows Safe Mode to bypass security tooling; at least one affiliate crashed systems while attempting EDR tampering (2025).
  • Reported abuse of Microsoft Intune to push ransomware during deployment (2025 vendor research).
  • Credential-based access: compromised credentials, brute forcing, and purchases from initial access brokers, per FBI/CISA advisory.
  • Post-access reconnaissance with network-scanning utilities (e.g., Advanced IP Scanner) before lateral movement.
Targeted sectors
ManufacturingProfessional/business servicesHealthcareEducationConstructionFinanceIT servicesBroadly targets SMBs and mid-market organizations across critical infrastructure
Notable public victims

Stanford University (claimed October 2023), Nissan Oceania (claimed December 2023), Recent dashboard-tracked leak-site victims (September 2026): Kyodo USA, Brentwood Country Club, CreateASoft, Brent Electric, Stransky Heiz-Mess-Regeltechnik GmbH

Estimated earnings

Approximately $42 million in ransom proceeds as of March 2024; no comprehensive public estimate since. — FBI/CISA joint cybersecurity advisory AA24-109A (published May 2024), citing ~$42 million in ransom proceeds as of March 2024.

Leak-site victims

VictimDiscoveredDetails
Renée Blanche · Dec 11, 2024
Nova Pole International Inc. · Dec 11, 2024
Matandy (matandy.com) · Dec 10, 2024
Corporación BJR · Dec 10, 2024
Conrey Insurance Brokers & Risk Managers · Dec 10, 2024
Aruba Productions · Dec 10, 2024
Lakeside Sod Supply · Dec 10, 2024
Proyectos y Seguros · Dec 10, 2024
Cipla · Dec 9, 2024
Consumers Builders Supply · Dec 9, 2024
ECBM · Dec 9, 2024
Pelstar · Dec 9, 2024
Pb Loader · Dec 9, 2024
Jamaica Bearings Group · Dec 9, 2024
Weinberg & Schwartz LLC · Dec 9, 2024
Milwaukee Cylinder · Dec 9, 2024
Davis Immigration Law Office · Dec 9, 2024
Séguin Haché SENCRL · Dec 9, 2024
Coffee Beanery · Dec 9, 2024
C Pathe · Dec 9, 2024
Tillamook Country Smoker (tcsmoker.com) · Nov 29, 2024
Pražské služby · Nov 29, 2024
Packard Machinery · Nov 29, 2024
Brookway Landscape &Irrigation · Nov 29, 2024
Aviosupport · Nov 29, 2024
Co-op Agro Centre · Nov 29, 2024
Bennett Porter Wealth Management Insurance · Nov 29, 2024
Wadsworth Solutions · Nov 29, 2024
AMI Consulting Engineers · Nov 29, 2024
HTT Packaging & Design · Nov 29, 2024
Thomas Greg & Sons Ltda · Nov 29, 2024
Sanderson Stewart · Nov 29, 2024
Touchstone Home Products · Nov 29, 2024
Astor Chocolate · Nov 29, 2024
McFarlane, Inc. · Nov 29, 2024
Summit Hosting · Nov 29, 2024
Kay & Burton · Nov 29, 2024
MSR Group · Nov 29, 2024
Deutsche Industrie Video System · Nov 29, 2024
First Chatham Bank · Nov 29, 2024
Metal Finishing · Nov 29, 2024
Plastic Recycling · Nov 29, 2024
North Shore Systems · Nov 29, 2024
Traffics · Nov 29, 2024
Colwell Colour (colwellcolour.com) · Nov 29, 2024
Magguilli Law Firm,PPLC · Nov 29, 2024
Turf Paradise · Nov 29, 2024
Zillertal Bier · Nov 29, 2024
CAUDURO SPORTS LTDA · Nov 29, 2024
Dfa Ny · Nov 29, 2024

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .