Threat Assessment: Howling Scorpius (Akira Ransomware)
ID: c95795db-859f-5a3c-bac1-b073e21dfa25
STIX ID: report--c95795db-859f-5a3c-bac1-b073e21dfa25
Feed Name: Palo Alto Networks Unit 42
Emerging in early 2023, the Howling Scorpius group (Akira RaaS) runs double‑extortion ransomware campaigns against small and medium organizations across North America, Europe and Australia, using Windows, Linux and ESXi encryptors (including Megazord and Akira_v2) to exfiltrate data, encrypt VMs, and pressure victims via Tor-based leak and negotiation sites; the report details attack lifecycle TTPs, includes numerous SHA256 IOCs, targeted industries and countries, and provides mitigation and detection guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
