LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1024: Akira

Akira is a ransomware variant and ransomware deployment entity active since at least March 2023.[1] Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement.[1][2] Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.[3][4][5]

EnterpriseG1024GroupObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G1024: Akira describes [Akira](https://attack.mitre.org/groups/G1024) is a ransomware variant and ransomware deployment entity active since at least March 2023.(Citation: Arctic Wolf Akira 2023) [Akira](https://attack.mitre.org/groups/G1024) uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement.(Citation: Arctic Wolf Akira 2023)(Citation: Secureworks GOLD SAHARA) [Akira](https://attack.mitre.org/groups/G102...

Executive priority

G1024: Akira is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G1024: Akira by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G1024: Akira appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Akira

Akira is a ransomware variant and ransomware deployment entity active since at least March 2023.[1] Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement.[1][2] Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.[3][4][5]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

17 rows
DomainIDNameRelationship / procedure
EnterpriseT1567.002Exfiltration to Cloud StorageSub-technique

Akira will exfiltrate victim data using applications such as Rclone.[2]

EnterpriseT1213.002SharepointSub-technique

Akira has accessed and downloaded information stored in SharePoint instances as part of data gathering and exfiltration activity.[2]

EnterpriseT1531Account Access Removal

Akira deletes administrator accounts in victim networks prior to encryption.[2]

EnterpriseT1482Domain Trust Discovery

Akira uses the built-in Nltest utility or tools such as AdFind to enumerate Active Directory trusts in victim environments.[1]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Akira has used legitimate names and locations for files to evade defenses.[5]

EnterpriseT1078Valid Accounts

Akira uses valid account information to remotely access victim networks, such as VPN credentials.[2][1][5]

EnterpriseT1018Remote System Discovery

Akira uses software such as Advanced IP Scanner and MASSCAN to identify remote hosts within victim networks.[1]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

Akira has used RDP for lateral movement.[5]

EnterpriseT1059.001PowerShellSub-technique

Akira has used PowerShell scripts for credential harvesting and privilege escalation.[5]

EnterpriseT1657Financial Theft

Akira engages in double-extortion ransomware, exfiltrating files then encrypting them, in order to prompt victims to pay a ransom.[3][4]

EnterpriseT1486Data Encrypted for Impact

Akira encrypts files in victim environments as part of ransomware operations.[3][4]

EnterpriseT1133External Remote Services

Akira uses compromised VPN accounts for initial access to victim networks.[2]

EnterpriseT1027.001Binary PaddingSub-technique

Akira has used binary padding to obfuscate payloads.[5]

EnterpriseT1685Disable or Modify Tools

Akira has disabled or modified security tools for defense evasion.[5]

EnterpriseT1219Remote Access Tools

Akira uses legitimate utilities such as AnyDesk and PuTTy for maintaining remote access to victim environments.[2][1]

EnterpriseT1560.001Archive via UtilitySub-technique

Akira uses utilities such as WinRAR to archive data prior to exfiltration.[2]

EnterpriseT1558Steal or Forge Kerberos Tickets

Akira have used scripts to dump Kerberos authentication credentials.[5]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0002: Mimikatz

Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. [1] [2]

Windows
ToolEnterprise

S0029: PsExec

PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.[1][2]

Windows
MalwareEnterprise

S1194: Akira _v2

Akira _v2 is a Rust-based variant of Akira ransomware that has been in use since at least 2024. Akira _v2 is designed to target VMware ESXi servers and includes a new command-line argument set and other expanded capabilities.[1][2][3]

MalwareEnterprise

S1129: Akira

Akira ransomware, written in C++, is most prominently (but not exclusively) associated with the ransomware-as-a-service entity Akira. Akira ransomware has been used in attacks across North America, Europe, and Australia, with a focus on critical infrastructure sectors including manufacturing, education, and IT services. Akira ransomware employs hybrid encryption and threading to increase the speed and efficiency of encryption and runtime arguments for tailored attacks. Notable variants include Rust-based Megazord for targeting Windows and Akira _v2 for targeting VMware ESXi servers.[1][2][3]

Windows
MalwareEnterprise

S1191: Megazord

Megazord is a Rust-based variant of Akira ransomware that has been in use since at least August 2023 to target Windows environments. Megazord has been attributed to the Akira group based on overlapping infrastructure though is possibly not exclusive to the group.[1][2][3]

Windows
ToolEnterprise

S0349: LaZagne

LaZagne is a post-exploitation, open-source tool used to recover stored passwords on a system. It has modules for Windows, Linux, and OSX, but is mainly focused on Windows systems. LaZagne is publicly available on GitHub.[1]

LinuxmacOSWindows
ToolEnterprise

S1040: Rclone

Rclone is a command line program for syncing files with cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA. Rclone has been used in a number of ransomware campaigns, including those associated with the Conti and DarkSide Ransomware-as-a-Service operations.[1][2][3][4][5]

LinuxWindowsmacOS
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
2.0
Created
Modified
Raw hash
3eea72fa163b3099...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.22.0Current bundle3eea72fa163b…
19.12.0Older bundle94a6589eab70…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Arctic Wolf Akira 2023

    Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.

    Open source URL
  2. [2]
    Secureworks GOLD SAHARA

    Secureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.

    Open source URL
  3. [3]
    BushidoToken Akira 2023

    Will Thomas. (2023, September 15). Tracking Adversaries: Akira, another descendent of Conti. Retrieved February 21, 2024.

    Open source URL
  4. [4]
    CISA Akira Ransomware APR 2024

    CISA et al. (2024, April 18). #StopRansomware: Akira Ransomware. Retrieved December 10, 2024.

    Open source URL
  5. [5]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  6. [6]
    Palo Alto Howling Scorpius DEC 2024

    Zemah, Y. (2024, December 2). Threat Assessment: Howling Scorpius (Akira Ransomware). Retrieved January 8, 2025.

    Open source URL
  7. [7]
    CrowdStrike PUNK SPIDER

    CrowdStrike. (n.d.). Punk Spider. Retrieved February 20, 2024.

    Open source URL
  8. [8]
    GOLD SAHARA

    (Citation: Secureworks GOLD SAHARA)

  9. [9]
    Howling Scorpius

    (Citation: Palo Alto Howling Scorpius DEC 2024)

  10. [10]
    PUNK SPIDER

    (Citation: CrowdStrike PUNK SPIDER)

  11. [11]
    mitre-attackG1024
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.