akira
ransomware group · aka Akira, Akira_VP (Linux/VMware ESXi variant), HDK / 'How Daemons Kill' (reported rebrand of its Linux encryptor, 2024) · Unknown; believed to be Russian-speaking. Some researchers have speculated links to former Conti-affiliated operators (unconfirmed). · active since March 2023
Akira is a ransomware and data-extortion group first observed in March 2023, known for double extortion and a dedicated leak site used to pressure non-paying victims. It primarily targets small and mid-sized organizations across multiple sectors in North America and Europe, gaining initial access through SSL VPNs and edge appliances (notably Cisco ASA/FTD and SonicWall) often without multi-factor authentication. The group operates both Windows and Linux/VMware ESXi encryptors (Akira_VP) and, per 2025 vendor reporting, has used Windows Safe Mode reboots and attempted EDR tampering to evade defenses. The FBI and CISA estimated roughly $42 million in ransom proceeds as of March 2024 (source: FBI/CISA joint advisory, 2024). The group remains active, with this dashboard tracking five new leak-site victims in the past seven days (last post 2026-09-09).
- Initial access via SSL VPNs/edge appliances lacking MFA; exploits Cisco ASA/FTD (CVE-2023-20269) and SonicWall SonicOS (CVE-2024-40766); 2025 reporting also links affiliates to SonicWall SSL VPN zero-day exploitation.
- Double extortion: data exfiltration followed by encryption; leak-site shaming of non-payers.
- Dual-platform encryptors: Windows locker plus Linux/VMware ESXi variant (Akira_VP).
- Exfiltration using cloud storage and transfer tools, including MEGA (MEGAsync) and Rclone, per FBI/CISA reporting.
- EDR evasion: rebooting hosts into Windows Safe Mode to bypass security tooling; at least one affiliate crashed systems while attempting EDR tampering (2025).
- Reported abuse of Microsoft Intune to push ransomware during deployment (2025 vendor research).
- Credential-based access: compromised credentials, brute forcing, and purchases from initial access brokers, per FBI/CISA advisory.
- Post-access reconnaissance with network-scanning utilities (e.g., Advanced IP Scanner) before lateral movement.
Stanford University (claimed October 2023), Nissan Oceania (claimed December 2023), Recent dashboard-tracked leak-site victims (September 2026): Kyodo USA, Brentwood Country Club, CreateASoft, Brent Electric, Stransky Heiz-Mess-Regeltechnik GmbH
Approximately $42 million in ransom proceeds as of March 2024; no comprehensive public estimate since. — FBI/CISA joint cybersecurity advisory AA24-109A (published May 2024), citing ~$42 million in ransom proceeds as of March 2024.
Leak-site victims1,494 posts · newest first
| Victim | Discovered | Details |
|---|---|---|
| RIMSS | · Aug 17, 2023 | — |
| The Clifton Public Schools | · Aug 17, 2023 | — |
| Cequint | · Aug 16, 2023 | — |
| Tally Energy Services | · Aug 16, 2023 | — |
| Rite Technology | · Aug 11, 2023 | — |
| The Belt Railway Company of Chicago | · Aug 10, 2023 | — |
| Optimum Technology | · Aug 10, 2023 | — |
| Boson | · Aug 10, 2023 | — |
| TIMECO | · Aug 9, 2023 | — |
| Räddningstjänsten Västra Blekinge | · Aug 7, 2023 | — |
| Papel Prensa SA | · Aug 7, 2023 | — |
| Koury Engineering | · Aug 4, 2023 | — |
| Venture General Agency | · Aug 3, 2023 | — |
| Datawatch Systems | · Aug 3, 2023 | — |
| TGRWA | · Aug 2, 2023 | — |
| Guido | · Aug 2, 2023 | — |
| Parathon by JDA eHealth Systems | · Aug 1, 2023 | — |
| Frost & Sullivan | · Jul 28, 2023 | — |
| Handi Quilter | · Jul 27, 2023 | — |
| Morehead State University (MSU) | · Jul 27, 2023 | — |
| Offutt Nord | · Jul 27, 2023 | — |
| Becht Engineering | · Jul 25, 2023 | — |
| El Milagro | · Jul 24, 2023 | — |
| SBM | · Jul 24, 2023 | — |
| Charles & Colvard Ltd. | · Jul 24, 2023 | — |
| Yamaha Canada Music Ltd | · Jul 21, 2023 | — |
| Bright Future Electric, LLC | · Jul 20, 2023 | — |
| Gerber ChildrenswearLLC | · Jul 13, 2023 | — |
| Schmidt Salzman & Moran, Ltd | · Jul 12, 2023 | — |
| A123 Systems | · Jul 11, 2023 | — |
| Hamre Schumann Mueller & Larson HSML | · Jul 10, 2023 | — |
| Green Diamond | · Jul 10, 2023 | — |
| Pinnergy | · Jul 6, 2023 | — |
| Murphy | · Jul 5, 2023 | — |
| Hospitality StaffingSolutions | · Jun 29, 2023 | — |
| LCG company (URGENT!) | · Jun 29, 2023 | — |
| Nycon | · Jun 29, 2023 | — |
| Wilcom | · Jun 28, 2023 | — |
| Stoughton Trailers | · Jun 28, 2023 | — |
| Chariton Valley | · Jun 26, 2023 | — |
| Knights of Old Group | · Jun 26, 2023 | — |
| London Capital Group(LCG) | · Jun 26, 2023 | — |
| The Akron-Summit County Public Library | · Jun 23, 2023 | — |
| Perpetual Group | · Jun 23, 2023 | — |
| Galveston College | · Jun 23, 2023 | — |
| Refractron | · Jun 22, 2023 | — |
| DBSA hit by ransomware attack. | · Jun 22, 2023 | — |
| GC&E | · Jun 22, 2023 | — |
| Yokohama-oht (atgtire) | · Jun 21, 2023 | — |
| Habasit | · Jun 21, 2023 | — |