Conti and Akira: Chained Together
ID: 6c6be578-a5e1-5a58-960b-eff8b8aadd07
STIX ID: report--6c6be578-a5e1-5a58-960b-eff8b8aadd07
Feed Name: Arctic Wolf Blog
Threat Score
Arctic Wolf Labs reports that Akira is a RaaS-operated ransomware group active since March 2023 that has compromised at least 63 organizations (about 80% SMBs), uses data exfiltration for double extortion, commonly gains access via compromised credentials (often where VPN MFA is not enabled), and that blockchain analysis links Akira ransom payments to Conti-affiliated wallets; the report assesses Akira as opportunistic and recommends security best practices such as enabling MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
