logo

Unraveling Akira Ransomware

ID: bb34f6db-f413-5056-87ae-93ba1f75edc1

STIX ID: report--bb34f6db-f413-5056-87ae-93ba1f75edc1

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2023-05-10

Date Updated: 2026-07-17

...
...

### Executive Summary: Akira ransomware is a newly observed double-extortion ransomware strain (active since April 2023) that encrypts files with a ".akira" extension, uses CryptoAPI (RSA/AES) with a hardcoded public key, deletes shadow copies via WMI/PowerShell, and exfiltrates data to a leak site; CRIL documents 15+ publicly disclosed victims across multiple industries, provides a sample SHA256, MITRE mappings, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.