LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1024: Akira

Akira is a ransomware variant and ransomware deployment entity active since at least March 2023.[1] Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement.[1][2] Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.[3][4][5]

EnterpriseG1024GroupObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Akira is documented by ATT&CK as a ransomware deployment entity associated with compromised credentials, single-factor external access such as VPNs, lateral movement using public tools, data theft before encryption, and double-extortion pressure. For leaders, the decision value is clear: resilience depends less on one malware signature and more on whether identity controls, remote access, Active Directory visibility, data-exfiltration monitoring, and recovery plans can withstand a credential-led ransomware intrusion.

Executive priority

Prioritize Akira as a ransomware-readiness use case for validating business continuity, identity hardening, and incident response decision-making. Executives should ask whether single-factor remote access still exists, whether privileged and domain credentials are monitored for abuse, whether sensitive data repositories such as SharePoint are covered by logging and governance, and whether recovery plans include Windows and VMware ESXi ransomware scenarios. Because ATT&CK notes double extortion, legal, communications, compliance, and data-loss response procedures should be exercised alongside technical restoration.

Technical view

ATT&CK does not provide a dedicated detection section for this group, so defenders should build coverage from the related behaviors and tools. Validate monitoring for compromised valid accounts and external remote services, especially VPN and RDP use; credential-access tooling such as Mimikatz and LaZagne; Active Directory discovery via tools such as AdFind and domain trust discovery; remote execution and remote access tooling such as PsExec and other legitimate remote access tools; PowerShell execution; archiving before exfiltration; Rclone or similar cloud-storage synchronization; ransomware execution including Akira, Megazord, and Akira _v2; and impact behaviors such as encryption and account access removal. Coverage should include both endpoint and identity/control-plane telemetry, with special attention to ESXi where Akira _v2 targeting is documented.

Likely telemetry

  • VPN, external remote service, and RDP authentication logs, including MFA status where available
  • Identity provider, Active Directory, Kerberos, and privileged-account activity logs
  • Endpoint process creation, command-line, script, and PowerShell logging
  • Remote administration and lateral movement evidence, including PsExec-like service creation or remote execution patterns
  • Credential dumping and stored-password recovery tool detections or behavioral traces

Detection direction

  • Start with identity-led intrusion detection: unusual successful logins to VPN or other external remote services, single-factor access paths, impossible travel, new device use, and anomalous privileged-account activity.
  • Correlate valid-account access with discovery and lateral movement: RDP sessions, PsExec-like remote execution, PowerShell activity, AdFind/domain trust queries, and remote system discovery should be reviewed as a sequence rather than isolated alerts.
  • Tune carefully for dual-use tools. PsExec, AdFind, Rclone, PowerShell, and remote access tools can be legitimate, so detection should emphasize unusual users, hosts, timing, command lines, destinations, volume, and proximity to credential or ransomware activity.
  • Add exfiltration-oriented analytics before encryption: archive creation followed by large outbound transfers to cloud storage services is highly relevant to the documented double-extortion pattern.
  • Validate ESXi and virtualization monitoring explicitly. ATT&CK notes Akira variants capable of targeting VMware ESXi, but many SOC programs have weaker hypervisor logging than endpoint logging.

Mitigation priorities

  • Eliminate or strongly control single-factor external access, especially VPN and remote services; require phishing-resistant or otherwise strong MFA where feasible.
  • Reduce credential blast radius through privileged access management, least privilege, service-account governance, credential hygiene, and monitoring for Kerberos abuse.
  • Harden and monitor Active Directory and remote administration pathways, including RDP, PsExec-like execution, and legitimate remote access tools.
  • Restrict and monitor unsanctioned cloud-storage synchronization and high-risk data egress, while maintaining business-approved exceptions.
  • Improve ransomware resilience with segmented backups, tested restoration, protected backup credentials, and recovery playbooks that include Windows and ESXi scenarios.
Additional notes and limits

The supplied ATT&CK object identifies Akira as a ransomware variant and deployment entity with aliases GOLD SAHARA, PUNK SPIDER, and Howling Scorpius. The most useful defensive framing is a credential-led ransomware intrusion that may include public tools, lateral movement, data collection, cloud-storage exfiltration, and encryption. Because many related tools are legitimate administration utilities, high-quality baselining and correlation are more important than single indicator matching.

ATT&CK provides no official detection text for this group, and the group object itself lists platforms and tactics as not specified. Platform guidance here is limited to the official description and related software/technique relationships, including Windows and VMware ESXi references. Local exposure, control effectiveness, and detection coverage must be confirmed from the organization’s own identity, endpoint, network, cloud, SaaS, and hypervisor telemetry.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Akira

Akira is a ransomware variant and ransomware deployment entity active since at least March 2023.[1] Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement.[1][2] Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.[3][4][5]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

17 rows
DomainIDNameRelationship / procedure
EnterpriseT1567.002Exfiltration to Cloud StorageSub-technique

Akira will exfiltrate victim data using applications such as Rclone.[2]

EnterpriseT1213.002SharepointSub-technique

Akira has accessed and downloaded information stored in SharePoint instances as part of data gathering and exfiltration activity.[2]

EnterpriseT1531Account Access Removal

Akira deletes administrator accounts in victim networks prior to encryption.[2]

EnterpriseT1482Domain Trust Discovery

Akira uses the built-in Nltest utility or tools such as AdFind to enumerate Active Directory trusts in victim environments.[1]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Akira has used legitimate names and locations for files to evade defenses.[5]

EnterpriseT1078Valid Accounts

Akira uses valid account information to remotely access victim networks, such as VPN credentials.[2][1][5]

EnterpriseT1558Steal or Forge Kerberos Tickets

Akira have used scripts to dump Kerberos authentication credentials.[5]

EnterpriseT1018Remote System Discovery

Akira uses software such as Advanced IP Scanner and MASSCAN to identify remote hosts within victim networks.[1]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

Akira has used RDP for lateral movement.[5]

EnterpriseT1059.001PowerShellSub-technique

Akira has used PowerShell scripts for credential harvesting and privilege escalation.[5]

EnterpriseT1657Financial Theft

Akira engages in double-extortion ransomware, exfiltrating files then encrypting them, in order to prompt victims to pay a ransom.[3][4]

EnterpriseT1486Data Encrypted for Impact

Akira encrypts files in victim environments as part of ransomware operations.[3][4]

EnterpriseT1133External Remote Services

Akira uses compromised VPN accounts for initial access to victim networks.[2]

EnterpriseT1027.001Binary PaddingSub-technique

Akira has used binary padding to obfuscate payloads.[5]

EnterpriseT1685Disable or Modify Tools

Akira has disabled or modified security tools for defense evasion.[5]

EnterpriseT1219Remote Access Tools

Akira uses legitimate utilities such as AnyDesk and PuTTy for maintaining remote access to victim environments.[2][1]

EnterpriseT1560.001Archive via UtilitySub-technique

Akira uses utilities such as WinRAR to archive data prior to exfiltration.[2]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0002: Mimikatz

Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. [1] [2]

Windows
ToolEnterprise

S0029: PsExec

PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.[1][2]

Windows
MalwareEnterprise

S1194: Akira _v2

Akira _v2 is a Rust-based variant of Akira ransomware that has been in use since at least 2024. Akira _v2 is designed to target VMware ESXi servers and includes a new command-line argument set and other expanded capabilities.[1][2][3]

MalwareEnterprise

S1129: Akira

Akira ransomware, written in C++, is most prominently (but not exclusively) associated with the ransomware-as-a-service entity Akira. Akira ransomware has been used in attacks across North America, Europe, and Australia, with a focus on critical infrastructure sectors including manufacturing, education, and IT services. Akira ransomware employs hybrid encryption and threading to increase the speed and efficiency of encryption and runtime arguments for tailored attacks. Notable variants include Rust-based Megazord for targeting Windows and Akira _v2 for targeting VMware ESXi servers.[1][2][3]

Windows
MalwareEnterprise

S1191: Megazord

Megazord is a Rust-based variant of Akira ransomware that has been in use since at least August 2023 to target Windows environments. Megazord has been attributed to the Akira group based on overlapping infrastructure though is possibly not exclusive to the group.[1][2][3]

Windows
ToolEnterprise

S0349: LaZagne

LaZagne is a post-exploitation, open-source tool used to recover stored passwords on a system. It has modules for Windows, Linux, and OSX, but is mainly focused on Windows systems. LaZagne is publicly available on GitHub.[1]

LinuxmacOSWindows
ToolEnterprise

S1040: Rclone

Rclone is a command line program for syncing files with cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA. Rclone has been used in a number of ransomware campaigns, including those associated with the Conti and DarkSide Ransomware-as-a-Service operations.[1][2][3][4][5]

LinuxWindowsmacOS
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.0
Created
Modified
Raw hash
94a6589eab709b93...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.0Current bundle94a6589eab70…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Arctic Wolf Akira 2023

    Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.

    Open source URL
  2. [2]
    Secureworks GOLD SAHARA

    Secureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.

    Open source URL
  3. [3]
    BushidoToken Akira 2023

    Will Thomas. (2023, September 15). Tracking Adversaries: Akira, another descendent of Conti. Retrieved February 21, 2024.

    Open source URL
  4. [4]
    CISA Akira Ransomware APR 2024

    CISA et al. (2024, April 18). #StopRansomware: Akira Ransomware. Retrieved December 10, 2024.

    Open source URL
  5. [5]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  6. [6]
    Palo Alto Howling Scorpius DEC 2024

    Zemah, Y. (2024, December 2). Threat Assessment: Howling Scorpius (Akira Ransomware). Retrieved January 8, 2025.

    Open source URL
  7. [7]
    Kersten Akira 2023

    Max Kersten & Alexandre Mundo. (2023, November 29). Akira Ransomware. Retrieved April 4, 2024.

    Open source URL
  8. [8]
    Arctic Wolf Akira 2023

    Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.

    Open source URL
  9. [9]
    Arctic Wolf Akira 2023

    Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.

    Open source URL
  10. [10]
    BushidoToken Akira 2023

    Will Thomas. (2023, September 15). Tracking Adversaries: Akira, another descendent of Conti. Retrieved February 21, 2024.

    Open source URL
  11. [11]
    BushidoToken Akira 2023

    Will Thomas. (2023, September 15). Tracking Adversaries: Akira, another descendent of Conti. Retrieved February 21, 2024.

    Open source URL
  12. [12]
    CISA Akira Ransomware APR 2024

    CISA et al. (2024, April 18). #StopRansomware: Akira Ransomware. Retrieved December 10, 2024.

    Open source URL
  13. [13]
    CISA Akira Ransomware APR 2024

    CISA et al. (2024, April 18). #StopRansomware: Akira Ransomware. Retrieved December 10, 2024.

    Open source URL
  14. [14]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  15. [15]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  16. [16]
    CrowdStrike PUNK SPIDER

    CrowdStrike. (n.d.). Punk Spider. Retrieved February 20, 2024.

    Open source URL
  17. [17]
    CrowdStrike PUNK SPIDER

    CrowdStrike. (n.d.). Punk Spider. Retrieved February 20, 2024.

    Open source URL
  18. [18]
    CrowdStrike PUNK SPIDER

    CrowdStrike. (n.d.). Punk Spider. Retrieved February 20, 2024.

    Open source URL
  19. [19]
    GOLD SAHARA

    (Citation: Secureworks GOLD SAHARA)

  20. [20]
    GOLD SAHARA

    (Citation: Secureworks GOLD SAHARA)

  21. [21]
    GOLD SAHARA

    (Citation: Secureworks GOLD SAHARA)

  22. [22]
    Howling Scorpius

    (Citation: Palo Alto Howling Scorpius DEC 2024)

  23. [23]
    Howling Scorpius

    (Citation: Palo Alto Howling Scorpius DEC 2024)

  24. [24]
    Howling Scorpius

    (Citation: Palo Alto Howling Scorpius DEC 2024)

  25. [25]
    PUNK SPIDER

    (Citation: CrowdStrike PUNK SPIDER)

  26. [26]
    PUNK SPIDER

    (Citation: CrowdStrike PUNK SPIDER)

  27. [27]
    PUNK SPIDER

    (Citation: CrowdStrike PUNK SPIDER)

  28. [28]
    Palo Alto Howling Scorpius DEC 2024

    Zemah, Y. (2024, December 2). Threat Assessment: Howling Scorpius (Akira Ransomware). Retrieved January 8, 2025.

    Open source URL
  29. [29]
    Palo Alto Howling Scorpius DEC 2024

    Zemah, Y. (2024, December 2). Threat Assessment: Howling Scorpius (Akira Ransomware). Retrieved January 8, 2025.

    Open source URL
  30. [30]
    Secureworks GOLD SAHARA

    Secureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.

    Open source URL
  31. [31]
    Secureworks GOLD SAHARA

    Secureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.

    Open source URL
  32. [32]
    mitre-attackG1024
    Open source URL
  33. [33]
    mitre-attackG1024
    Open source URL
  34. [34]
    mitre-attackG1024
    Open source URL
  35. [35]
    Secureworks GOLD SAHARA

    Secureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.

    Open source URL
  36. [36]
    Secureworks GOLD SAHARA

    Secureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.

    Open source URL
  37. [37]
    Secureworks GOLD SAHARA

    Secureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.

    Open source URL
  38. [38]
    Secureworks GOLD SAHARA

    Secureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.

    Open source URL
  39. [39]
    Secureworks GOLD SAHARA

    Secureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.

    Open source URL
  40. [40]
    Secureworks GOLD SAHARA

    Secureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.

    Open source URL
  41. [41]
    Arctic Wolf Akira 2023

    Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.

    Open source URL
  42. [42]
    Arctic Wolf Akira 2023

    Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.

    Open source URL
  43. [43]
    Arctic Wolf Akira 2023

    Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.

    Open source URL
  44. [44]
    Arctic Wolf Akira 2023

    Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.

    Open source URL
  45. [45]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  46. [46]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  47. [47]
    Arctic Wolf Akira 2023

    Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.

    Open source URL
  48. [48]
    Arctic Wolf Akira 2023

    Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.

    Open source URL
  49. [49]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  50. [50]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  51. [51]
    Secureworks GOLD SAHARA

    Secureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.

    Open source URL
  52. [52]
    Secureworks GOLD SAHARA

    Secureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.

    Open source URL
  53. [53]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  54. [54]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  55. [55]
    Arctic Wolf Akira 2023

    Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.

    Open source URL
  56. [56]
    Arctic Wolf Akira 2023

    Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.

    Open source URL
  57. [57]
    Arctic Wolf Akira 2023

    Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.

    Open source URL
  58. [58]
    Arctic Wolf Akira 2023

    Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.

    Open source URL
  59. [59]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  60. [60]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  61. [61]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  62. [62]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  63. [63]
    BushidoToken Akira 2023

    Will Thomas. (2023, September 15). Tracking Adversaries: Akira, another descendent of Conti. Retrieved February 21, 2024.

    Open source URL
  64. [64]
    BushidoToken Akira 2023

    Will Thomas. (2023, September 15). Tracking Adversaries: Akira, another descendent of Conti. Retrieved February 21, 2024.

    Open source URL
  65. [65]
    CISA Akira Ransomware APR 2024

    CISA et al. (2024, April 18). #StopRansomware: Akira Ransomware. Retrieved December 10, 2024.

    Open source URL
  66. [66]
    CISA Akira Ransomware APR 2024

    CISA et al. (2024, April 18). #StopRansomware: Akira Ransomware. Retrieved December 10, 2024.

    Open source URL
  67. [67]
    Arctic Wolf Akira 2023

    Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.

    Open source URL
  68. [68]
    Arctic Wolf Akira 2023

    Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.

    Open source URL
  69. [69]
    CISA Akira Ransomware APR 2024

    CISA et al. (2024, April 18). #StopRansomware: Akira Ransomware. Retrieved December 10, 2024.

    Open source URL
  70. [70]
    CISA Akira Ransomware APR 2024

    CISA et al. (2024, April 18). #StopRansomware: Akira Ransomware. Retrieved December 10, 2024.

    Open source URL
  71. [71]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  72. [72]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  73. [73]
    Palo Alto Howling Scorpius DEC 2024

    Zemah, Y. (2024, December 2). Threat Assessment: Howling Scorpius (Akira Ransomware). Retrieved January 8, 2025.

    Open source URL
  74. [74]
    Palo Alto Howling Scorpius DEC 2024

    Zemah, Y. (2024, December 2). Threat Assessment: Howling Scorpius (Akira Ransomware). Retrieved January 8, 2025.

    Open source URL
  75. [75]
    BushidoToken Akira 2023

    Will Thomas. (2023, September 15). Tracking Adversaries: Akira, another descendent of Conti. Retrieved February 21, 2024.

    Open source URL
  76. [76]
    BushidoToken Akira 2023

    Will Thomas. (2023, September 15). Tracking Adversaries: Akira, another descendent of Conti. Retrieved February 21, 2024.

    Open source URL
  77. [77]
    CISA Akira Ransomware APR 2024

    CISA et al. (2024, April 18). #StopRansomware: Akira Ransomware. Retrieved December 10, 2024.

    Open source URL
  78. [78]
    CISA Akira Ransomware APR 2024

    CISA et al. (2024, April 18). #StopRansomware: Akira Ransomware. Retrieved December 10, 2024.

    Open source URL
  79. [79]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  80. [80]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  81. [81]
    Kersten Akira 2023

    Max Kersten & Alexandre Mundo. (2023, November 29). Akira Ransomware. Retrieved April 4, 2024.

    Open source URL
  82. [82]
    CISA Akira Ransomware APR 2024

    CISA et al. (2024, April 18). #StopRansomware: Akira Ransomware. Retrieved December 10, 2024.

    Open source URL
  83. [83]
    CISA Akira Ransomware APR 2024

    CISA et al. (2024, April 18). #StopRansomware: Akira Ransomware. Retrieved December 10, 2024.

    Open source URL
  84. [84]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  85. [85]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  86. [86]
    Palo Alto Howling Scorpius DEC 2024

    Zemah, Y. (2024, December 2). Threat Assessment: Howling Scorpius (Akira Ransomware). Retrieved January 8, 2025.

    Open source URL
  87. [87]
    Palo Alto Howling Scorpius DEC 2024

    Zemah, Y. (2024, December 2). Threat Assessment: Howling Scorpius (Akira Ransomware). Retrieved January 8, 2025.

    Open source URL
  88. [88]
    Secureworks GOLD SAHARA

    Secureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.

    Open source URL
  89. [89]
    Secureworks GOLD SAHARA

    Secureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.

    Open source URL
  90. [90]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  91. [91]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  92. [92]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  93. [93]
    Arctic Wolf Akira 2023

    Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.

    Open source URL
  94. [94]
    Secureworks GOLD SAHARA

    Secureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.

    Open source URL
  95. [95]
    Arctic Wolf Akira 2023

    Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.

    Open source URL
  96. [96]
    Arctic Wolf Akira 2023

    Steven Campbell, Akshay Suthar, & Connor Belfiorre. (2023, July 26). Conti and Akira: Chained Together. Retrieved February 20, 2024.

    Open source URL
  97. [97]
    Secureworks GOLD SAHARA

    Secureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.