logo

Akira Ransomware Extends Reach to Linux Platform

ID: a4170f3c-ce2a-5b13-ab09-dd439f67d70c

STIX ID: report--a4170f3c-ce2a-5b13-ab09-dd439f67d70c

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-11-17

Date Updated: 2026-07-16

...
...

Cyble Research and Intelligence Labs reports that the Akira ransomware, previously focused on Windows, has expanded to include a 64-bit Linux ELF variant (SHA256: 1d3b5c650533d13c81e325972a912e3ff8776e36e18bca966dae50735f8ab296). The report provides technical analysis (command-line parameters, hardcoded RSA public key, AES/CAMELLIA/IDEA/DES routines), a comprehensive list of targeted file extensions, observed victims (~46 publicly disclosed plus 30 additional identified, largely in the United States), MITRE ATT&CK mappings, IOCs, and recommended defensive measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.