logo

Akira Ransomware

ID: b40ae593-e1ab-521c-b741-a228ca644257

STIX ID: report--b40ae593-e1ab-521c-b741-a228ca644257

Feed Name: FortiGuard Labs | FortiGuard Center - Outbreak Alerts

Threat Score
80/100

Date Published: 2025-11-13

Date Updated: 2026-07-28

...
...

Akira ransomware (active since early 2023) has targeted over 250 organizations across multiple regions and extorted approximately $42M using Ransomware-as-a-Service and double extortion techniques; actors exploit exposed VPN/RDP/Cisco vulnerabilities and credential theft to gain access, deploy variants (original C++ Akira and Rust-based Megazord/Akira_v2), and exfiltrate and encrypt data. The report lists multiple CVEs tied to exploitation, references advisories from CISA/FBI/Europol, and recommends patching and vendor detection mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.