logo

Akira ransomware is encrypting victims again following pure extortion fling

ID: 0bec0d05-d9b2-5749-8f50-8cabcf7004ba

STIX ID: report--0bec0d05-d9b2-5749-8f50-8cabcf7004ba

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2024-10-22

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Researchers at Cisco Talos report that the Akira ransomware operation has reverted to encrypting victims' files after periods of data-only extortion and has consolidated its encryptor toolset (C++ and Rust variants); the group leverages RaaS affiliates to exploit high-impact vulnerabilities (including CVE-2024-40766), compromised VPN credentials, and various social-engineering techniques to target Windows, Linux and ESXi environments, posing a significant operational risk to enterprises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.