Akira Dual-Platform Ransomware: Active Targeting of Finance, Healthcare, and Critical Infrastructure
Source report →Active since March 2023, Akira is a ransomware-as-a-service group that has claimed more than 250 victims across North America, Europe, and Australia, accumulating over $42 million in confirmed ransom proceeds. The group targets organizations across critical infrastructure, financial services, healthcare, manufacturing, and education, and operates a dedicated leak site to pressure victims through double extortion. Notably, Akira deploys separate encryptors for Windows and VMware ESXi environments, meaning backup infrastructure is as much a target as production systems.
Akira gains initial access primarily through unpatched internet-facing appliances and VPN endpoints lacking multi-factor authentication, with Cisco ASA/FTD vulnerabilities and Veeam backup server weaknesses being documented entry points. Once inside, credential harvesting is a core focus: operators use public tooling like Mimikatz alongside purpose-built scripts targeting Veeam backup credentials to collect domain account material. Privilege escalation to domain administrator level follows quickly, with new accounts created to maintain persistent access alongside legitimate remote management tools like AnyDesk and covert tunnels via Ngrok.
Before deploying their encryptor, Akira operators invest time in defense evasion and data staging. Windows Defender is disabled and exclusions are added through registry modifications, while data is compressed using WinRAR and exfiltrated to cloud storage. Volume shadow copies are deleted to eliminate recovery options, after which the encryptor is deployed across Windows endpoints and ESXi hosts. Victims who pay still face the risk of public data exposure: the group publishes stolen data regardless of ransom outcome.
IOCs (59)
Scan your environment for IOCs →SHA256 FILE HASH 41
d2fd0654710c27dcf37b6c1437880020824e161dd0bf28e3a133ed777242a0cadcfa2800754e5722acf94987bb03e814edcb9acebda37df6da1987bf48e5b05e3298d203c2acb68c474e5fdad8379181890b4403d6491c523c13730129be3f750ee1d284ed663073872012c7bde7fac5ca1121403f1a5d2d5411317df282796cffd9f58e5fe8502249c67cad0123ceeeaa6e9f69b4ec9f9e21511809849eb8fcdfe6fddc67bdc93b9947430b966da2877fda094edf3e21e6f0ba98a84bc53198131da83b521f610819141d5c740313ce46578374abb22ef504a7593955a65f079f393516edf6b8e011df6ee991758480c5b99a0efbfd68347786061f0e04426c9585af44c3ff8fd921c713680b0c2b3bbc9d56add848ed62164f7c9b9f23d0652f629395fdfa11e713ea8bf11d40f6f240acf2f5fcf9a2ac50b6f7fbc7521c837f731cc11f8e4d249142e99a44b9da7a48505ce32c4ee4881041beeddb3760be95477703e789e6182096a09bc98853e0a70b680a4f19fa2bf86cbb9280e8ec5a0c0e0f9b09b80d87ebc88e2870907b6cacb4cd7703584baf8f2be1fd9438696dc9c94ac5e1991a7db42c7973e328fceeb6f163d9f644031bdfd4123c7b3898b0aaa6041912a6ba3cf167ecdb90a434a62feaf08639c59705847706b9f492015d18051333e658c4816ff3576a2e9d97fe2a1196ac0ea5ed9ba386c46defafdb885e1e3bf6999126ae4aa52146280fdb913912632e8bac4f54e98c58821a307d3258359209e215a9fc0dafd14039121398559790dba9aa2398c457348ee1cb8a4dcf3465d7e49b609defa1e2b6cfcc86ffa30c72246cb2744dbf50736c5f3d74d558afef43cec0ee7a2fbfd9cdd5b71f55f971672d5e523a400b82b98c752ca5b78e12c8eb39cec9a414b56a36acbcc1a5b31dc96a38bc668138a00f94f7c26ea5bfd5fc6cd3dea74738ac7025fa14ea844f400708df2293572796568f65bd6b614dc9f9684f715f50946e85557b82af80fcb45576efad47eee1bf054c15e570f07266e2afb5c70788c018d684698b0940eded4cb863f2b33f4edd31b59d1eab1dc0f706ff43936c1bb19db4f39b11129c3fc8ddafbd159852475ef99a246b2f793a25d3f82651567e5760e48ad06c9f6caab4f9fdc071e98919163b3a71e67168cfa209d56e296c40b32815270060e539963d68cda3285c5f393c97eb3c960d3777d48e8c13ce066b197905cc8fc69969af69b74d25f5e95dcd1302ada2e7ccec0b5b31af5956158bfbd14f6cbf4f1bca23c5d16a40dbf3758f3289146c565f430d700ca5f6cc093de4abba9410480ee7a8870d5e8fe86c9ce103eec3872f225fa2df5477cf924bd41241a3326060cc2f913aff2379858b148ddec455e4da67bc03aa12ac2884251aa24bf0ccd854047de403591a8537e6aba19e822807e06a452e88e55cc8ee364bf90e7a51671366efb3dac3e9468005b044164ba0f162442240221e1c2e0c09bc6104548ee847b6ec790413d6ece06ad675fff87e5b8dc1d55ea65e2bb9d245913ad69ce90e3bd9647eb16d992301145372565486c77568a2643061ac0b51f8c77f2ed202dc91afb9879f796ddd974489209d45f84f6445626f9d50bab16b2532f4683eeb76bd25449d83bdd6c85bf0b05f716a4b49584f84fef09b0aa37cbdb6a8f60a6bd8b473a7e5bffdc7fd2e952444f781574abccf64e1321a4b2b104f31aceaf4b19c5559e40ba35b73a754d3ae13d8e90c53146c0f74f497088b49b745e6377b32ed5d9dfaef3c84c7c0bb50fabf30363ad2e0bfb13d2b58ef6df743ce58669d7387ff94740ceb0122c4fc1c4ffd81af00e72e60a4SHA1 FILE HASH 4
5961a99181df157b81d35a50eeb27f96577a2fa2d5efaa22a74aab87d17f8666686b554e41fb389a08cf869a19c76ca718ba80ef73636e7bc38218b8ef328f68c6d865ba4ef4223b5d8ee9efb5667420MD5 FILE HASH 6
57d1aeb41d9cfea4d6899724bc4b09a517c624693f5dd575485ec4286b0ba786c56b31c9080b993d57c100b91d096c332fed7579556f01161bb1fdfd1c3e9e6c24e19d29a47b6b5e1a39bf5e4c313194814310fb7a59f23e3e137ee6fee04fa1FILE NAME 8
VeeamHax.exeVeeam-Get-Creds.ps1qKtul.vbss64.dlllck.exeWin_locker_0234-BMMNBW-MONC.exelevel-windows-amd64.exeLadon.exeDetections (10)
Enable detections →Connect your environment for suggestions and queries personalized to your security telemetry.
- Identification of Mimikatz Execution & Artifacts
- LSASS Memory Dump via comsvcs.dll (rundll32)
- User Added to Domain Administrators Groups
- Process Connection to MEGA Domain
- Account Created and Granted Privileged Role
- Windows Defender Tampering in Registry via reg.exe
- Windows Defender Folder Exclusion Added Via reg.exe
- PSExec Execution
- Password Spray Across Multiple Accounts