logo

Threat Brief: Understanding Akira Ransomware

ID: 0c69fd41-4edd-5229-b477-cd0e4276bca5

STIX ID: report--0c69fd41-4edd-5229-b477-cd0e4276bca5

Feed Name: Qualys Blog

Threat Score
80/100

Date Published: 2024-10-02

Date Updated: 2026-04-28

Author: Akshat Pradhan

...
...

Akira is an active Ransomware-as-a-Service observed since March 2023 and linked to Conti affiliates; attackers use compromised credentials and public-facing exploits to gain access, perform AD/network reconnaissance, dump credentials, move laterally (RDP, PsExec), exfiltrate and leak data, delete backups/shadow copies, and encrypt files. The report includes a sample MD5, IoCs, MITRE ATT&CK mappings, command-line and behavioral indicators, and detection/hunting queries and EDR recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.