logo

Akira Ransomware Indicators | Huntress

ID: d386e7e4-2c7f-56d9-8b81-394563d17022

STIX ID: report--d386e7e4-2c7f-56d9-8b81-394563d17022

Feed Name: Huntress Blog

Threat Score
78/100

Date Published: 2024-09-20

Date Updated: 2026-04-28

...
...

Huntress analysts report recurring Akira ransomware activity: attackers create hidden or new accounts, enable or use RDP, install Cloudflared tunnels for remote access, and ultimately deploy a w.exe encryptor that produces files with the .akira extension and an akira_readme.txt ransom note. The report lists concrete IOCs (e.g., WIN-JGRMF8L11HO workstation name, Noface66Nocase! password, a w.exe SHA256), shows example malicious commands, and recommends inventory, attack-surface reduction, and MDR/SIEM monitoring to detect and prevent encryption events.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.