EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/ransomware-attack/akira-ransomware
142/430

File EL-0289HighOngoingRansomware Attack / Crypto-locker/Extortionware

Akira Ransomware

Also filed as Akira CryptoLocker

Akira Ransomware is a crypto-locker strain that emerged around late 2022, targeting organizations globally. It encrypts victim files and systems, demanding a ransom payment in cryptocurrency for the decryption key. The group is known for its aggressive deployment and focus on high-value corporate targets.

  • #ransomware
  • #crypto-locker
  • #extortion
  • #data-encryption
  • #cybercrime
Notoriety6/10
Event
1 Jan 2023
Disclosed
1 Jan 2023
Target
Organizations Worldwide
Actor
Akira Group
Scale
Variable (System-wide)
Status
Ongoing

01Summary

The Akira Ransomware campaign gained notoriety for its sophisticated encryption methods and its ability to infiltrate diverse corporate networks. Attackers typically gain initial access through exploited vulnerabilities or successful phishing campaigns, allowing them to establish persistence within the victim's environment. Once inside, the group performs lateral movement, escalating privileges to compromise domain controllers and critical servers. The ransomware payload then executes, encrypting file shares, databases, and virtual machines. The attackers often employ double extortion tactics, exfiltrating sensitive data before encryption and threatening to publish it if the ransom is not paid, significantly increasing the pressure on victims to pay.

02Background

Ransomware targeting the corporate sector has seen a dramatic increase in sophistication since 2020. Akira Ransomware represents a modern iteration of this trend, leveraging Ransomware-as-a-Service (RaaS) models. These models lower the barrier to entry for cybercriminals, allowing less skilled actors to deploy highly destructive, professional-grade malware.

03Key revelations

  1. 01The use of double extortion, threatening to leak stolen data.
  2. 02The targeting of critical infrastructure and large multinational corporations.
  3. 03The reliance on RaaS models, making the threat accessible to lower-tier criminal groups.

04Technical analysis

Akira Ransomware utilizes strong, modern encryption algorithms (e.g., AES-256 or similar) to render files inaccessible. The ransomware payload is often delivered via custom loaders or exploiting known vulnerabilities in VPNs or remote desktop services. The group's operational security suggests they purchase initial access credentials from other criminal groups, indicating a supply chain model for initial compromise.

Attack vector
Exploited vulnerabilities (e.g., VPNs, RDP), Phishing/Spear-phishing, Compromised Credentials
Attack method
Encryption and Extortion (Double Extortion)
Initial access
Phishing or Exploitation
Lateral movement
Pass-the-Hash, Exploiting Network Protocols
Persistence
Scheduled Tasks, Registry Modification
Exfiltration
SMB/FTP/Cloud Storage APIs
Tool / malware
Akira Ransomware
Malware family
Akira
Malware type
Ransomware

MITRE ATT&CK techniques

  • T1566.001
  • T1078
  • T1021

05Threat actor

The Akira Group operates as a sophisticated Ransomware-as-a-Service (RaaS) operation. They maintain a decentralized structure, where core developers provide the malware and infrastructure, while affiliates handle the initial access, deployment, and negotiation with victims. Their primary goal is maximizing financial yield through comprehensive data theft and encryption.

Aliases

  • Akira CryptoLocker

MITRE groups

  • T1486

06Victims and impact

Countries affected

  • Global

07Data exposed

Data types

  • Credentials
  • Financial Records
  • Source Code
  • PII
  • Confidential Documents

Notable documents

  • Ransom Note (README.txt)
  • Decryption Instructions

08Financial damage

Damage is estimated based on operational downtime and recovery costs, which are highly variable.

09Timeline

  1. 2022-12-01Initial observed activity and deployment of the ransomware strain.
  2. 2023-01-01Widespread public disclosure and increased reporting of successful attacks.

10Reaction and fallout

Public reaction

The public reaction has been one of heightened awareness regarding cyber risk, leading to increased calls for better corporate cybersecurity hygiene and government regulation.

Political impact

The incident has intensified political debates regarding the need for mandatory minimum cybersecurity standards for critical infrastructure sectors, particularly in Western nations.

Geopolitical consequences

It highlights the global nature of cybercrime, making national borders irrelevant for criminal operations and increasing the need for international cooperation in law enforcement.

11Legal

Legal outcomes are typically limited to the recovery of funds or the prosecution of the RaaS operators, which often operate across multiple jurisdictions, complicating extradition and prosecution efforts.

Civil lawsuits

  • Class action lawsuits against affected companies seeking damages for data loss and operational downtime.

12Aftermath

Policy changes

  • Increased adoption of Zero Trust Architecture (ZTA) principles in corporate security policies.

Regulatory changes

  • Strengthening of data breach notification laws (e.g., GDPR enforcement).

Security improvements

  • Mandatory implementation of Multi-Factor Authentication (MFA) across all remote access points.
  • Enhanced network segmentation to limit lateral movement.

13Significance and legacy

Significance

Akira Ransomware exemplifies the maturation of the Ransomware-as-a-Service (RaaS) model. It demonstrated the shift from simple encryption to sophisticated, multi-stage attacks involving data exfiltration and double extortion, setting a new, higher bar for corporate cyber resilience.

Legacy

The ransomware threat landscape has permanently shifted towards 'extortion-first' attacks. Organizations must now budget not only for prevention but also for rapid, resilient recovery and comprehensive incident response planning.

14Related files

Related events

  • DarkSide Ransomware
  • LockBit Ransomware

Inspired by

  • colony-locker
  • ryuk-ransomware

15Field notes

  1. 01The group often uses legitimate remote administration tools (like PowerShell or RDP) to blend malicious activity with normal network traffic.
  2. 02The use of cryptocurrency like Monero is preferred by some affiliates due to its superior privacy features compared to Bitcoin.

16Resolution

Recovery requires restoring from immutable backups and implementing significant security architecture changes to prevent re-infection.

17Sources

Official documents

  • CISA Advisories on Ransomware Mitigation

References

  1. [1]Cybersecurity Vendor Threat Reports
  2. [2]FBI Internet Crime Complaint Center (IC3) Alerts
Fact sheetEL-0289

Dates

Event
1 Jan 2023
Started
1 Dec 2022
Discovered
1 Jan 2023
Disclosed
1 Jan 2023
Ongoing
No

Target

Organisation
Organizations Worldwide
Type
Corporation
Sector
Mixed
Country
Global

Actor

Name
Akira Group
Type
Ransomware Gang
Motivation
Financial gain through data encryption and extortion
Attribution
Low
Status
Active
Arrested
No
Convicted
No

Data

Volume
Variable (System-wide)
Sensitivity
Confidential
Published
No

Money

Crypto
Bitcoin (BTC) or Monero (XMR)

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.