logo

Akira-Style Ransomware Campaign Hits Windows Users Across South America

ID: 9ef3eb58-9a51-523e-a6f3-c55470f4a31b

STIX ID: report--9ef3eb58-9a51-523e-a6f3-c55470f4a31b

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-04-02

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A Babuk-derived ransomware campaign impersonating the Akira group is actively targeting Windows users and organizations across South America by mimicking Akira branding (including .akira file extensions and Tor-based ransom contacts); technical analysis shows the encryptor is modified from leaked Babuk code rather than Akira’s original codebase, and defenders are advised to patch systems, use strong endpoint protection, maintain offline backups, and monitor for suspicious encryption activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.