THREATOPS Actor Dossier
LIVE ← Dashboard

Akira

G102475 reports
aliases · Akira · GOLD SAHARA · PUNK SPIDER · Howling Scorpius
Export dossier:
75
Reports
12
Techniques
8
Tactics
17
Countries
79%
Hunt coverage
4
Aliases

Analyst assessment — key judgments

  • Signature techniques: T1588.006 (Vulnerabilities), T1589.001 (Credentials), T1608.006 (SEO Poisoning).
  • Primary targeting: US, DE, GB, KR.
  • Tooling observed: akira.
  • Steady activity: 41 report(s) in last 30d vs 27 prior (+52%).
  • Recent movement: 13 new infrastructure indicator(s) in the last 30 days.
  • Hunt coverage 79% of 14 observed techniques (3 gap(s)).
  • Assessment confidence: medium (61).

Activity & trend

SteadyLast 30d: 41 vs 27 prior (+52%)· first reported 2025-08-05 · last 2026-09-18
10
7d
41
30d
73
90d
75
All
5.7
Rpts/wk
Reporting timeline · 12 months

Movement — last 30 days

Dropped (90d+)
T1608.006
Targeting lost
ARBRCHCNESFRIDITKRMXPK
New infrastructure
anderson-industries.commaximizedrevenue.comlazyboyz.noakstamping.comgeorgecameronnash.combykconstruction.comcetylite.comcgpmep.comseabrookisland.comgillrockdrill.comwinter-ingenieure.dedavisferber.com

Vulnerabilities in this actor's reporting · 18

Overview

Analyst triage
Intelligence summary

Akira is a ransomware variant and ransomware deployment entity active since at least March 2023.(Citation: Arctic Wolf Akira 2023) Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement.(Citation: Arctic Wolf Akira 2023)(Citation: Secureworks GOLD SAHARA) Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.(Citation: BushidoToken Akira 2023)(Citation: CISA Akira Ransomware APR 2024)(Citation: Cisco Akira Ransomware OCT 2024)

Top co-occurring indicators
    Aliases & naming
      Targeting · countries
        Targeting · named victims

          ATT&CK technique matrix

          Coverage vs hunt library:
          Hunt-coverage gaps — prioritized

            Top techniques by observation

            Threat catalogue · engineering roadmap0

            Flagged detection-engineering queue

            Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.

              No techniques queued yet — flag a gap above to add it here.

              Infrastructure

              IOC type mix
              Tooling / malware families
                Tracked infrastructure

                Relationships

                Related actors (behavioral cluster)
                  Attributed malware
                  Campaigns
                  No behavioral cluster, attributed malware, or campaigns recorded for this actor yet.

                  Activity

                  30-day mention timeline
                  Recent reporting
                  TitleSourceSeverityCollected