logo

New Akira Lookalike Ransomware Campaign Targeting Windows Users in South America

ID: f6682350-ece7-52b8-ad93-5367ced72a99

STIX ID: report--f6682350-ece7-52b8-ad93-5367ced72a99

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-04-02

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A Babuk-based ransomware campaign targeting Windows systems in South America is impersonating the Akira family by appending a .akira extension and deploying ransom notes with Akira-like Tor URLs and messaging; this deception aims to mislead victims and investigators. ESET researchers identified the Babuk-derived encryptor behind the campaign and recommend patching, network segmentation, offline backups, and monitoring for the .akira extension as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.