logo

Tracking Adversaries: Akira, another descendent of Conti

ID: 8e76330f-833f-540a-88f5-614daa7d8d08

STIX ID: report--8e76330f-833f-540a-88f5-614daa7d8d08

Feed Name: BushidoToken Blog

Threat Score
78/100

Date Published: 2024-03-06

Date Updated: 2026-06-12

...
...

This report analyzes the Akira ransomware campaign (emerging March 2023), documenting at least 63 known victims across sectors (SMBs, healthcare, education, finance, manufacturing) and describing technical capabilities (Windows domain and VMware/ESXi targeting, multiple ransomware builds including C++ and Rust variants, file extensions ".akira" and ".powerranges", and ransom note names). It details common TTPs and tooling (brute-forced VPNs, Fortinet exploits, credential theft tools like Mimikatz/LaZagne, lateral movement via PsExec/Impacket, SystemBC RAT, exfiltration via Rclone/FTP, Cloudflared/ngrok C2), Akira’s Tor negotiation and DLS sites (including use of magnet links), and presents multi-level evidence linking Akira to Conti, including code similarities, shared tooling and playbook behavior, and blockchain transactions moving ransom funds to Conti-affiliated wallets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.