Ransomware Group intelligence
Akira
ActiveTrack Akira with 1703 published victims and 2 known leak locations in a single intelligence view.
Overview
Akira is tracked by Breach House as a ransomware group with 1703 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 48 3.0%
- Pending 1569 97.0%
- Deleted 0 0.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Up checked 3h ago | akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion |
| Leak location 1 | Onion service | Up checked 3h ago | akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion |
Top Activity Sectors (18)
- Finance / Legal / Insurance 427
- Communication / Marketing 320
- Manufacturing / Engineering 172
- Services 130
- Construction / Real Estate 106
- Not identified 75
- IT 66
- Healthcare / Pharma 66
- Energy 40
- Transportation / Travel / Logistics 33
- Hospitality / Food & Beverage / Tourism 33
- Agriculture / Food 32
- Retail / E-commerce 29
- Telecommunications 28
- Education 25
- Public Sector 16
- NGOs / Associations 5
- null 1
Typical Attacks (29)
▼How Akira typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Akira, Akira, Akira _v2.
-
What they do: Akira uses valid account information to remotely access victim networks, such as VPN credentials.
What that means: Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: Akira uses compromised VPN accounts for initial access to victim networks.
What that means: Adversaries may leverage external-facing remote services to initially access and/or persist within a network.
-
T1047 Windows Management Instrumentation Execution
What they do: Akira will leverage COM objects accessed through WMI during execution to evade detection.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.001 PowerShell Execution
What they do: Akira has used PowerShell scripts for credential harvesting and privilege escalation.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: Akira executes from the Windows command line and can take various arguments for execution.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1106 Native API Execution
What they do: Akira executes native Windows functions such as GetFileAttributesW and `GetSystemInfo`.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: Akira _v2 can create a child process for encryption.
What that means: Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence.
-
T1027.001 Binary Padding Stealth
What they do: Akira has used binary padding to obfuscate payloads.
What that means: Adversaries may use binary padding to add junk data and change the on-disk representation of malware.
-
T1036.005 Match Legitimate Resource Name or Location Stealth
What they do: Akira has used legitimate names and locations for files to evade defenses.
What that means: Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
-
T1480 Execution Guardrails Stealth
What they do: Akira _v2 will fail to execute if the targeted `/vmfs/volumes/` path does not exist or is not defined.
What that means: Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Akira has disabled or modified security tools for defense evasion.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1558 Steal or Forge Kerberos Tickets Credential Access
What they do: Akira have used scripts to dump Kerberos authentication credentials.
What that means: Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket.
-
T1018 Remote System Discovery Discovery
What they do: Akira uses software such as Advanced IP Scanner and MASSCAN to identify remote hosts within victim networks.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1057 Process Discovery Discovery
What they do: Akira verifies the deletion of volume shadow copies by checking for the existence of the process ID related to the process created to delete these items.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1082 System Information Discovery Discovery
What they do: Akira uses the GetSystemInfo Windows function to determine the number of processors on a victim machine.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: Akira examines files prior to encryption to determine if they meet requirements for encryption and can be encrypted by the ransomware.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1135 Network Share Discovery Discovery
What they do: Akira can identify remote file shares for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1482 Domain Trust Discovery Discovery
What they do: Akira uses the built-in Nltest utility or tools such as AdFind to enumerate Active Directory trusts in victim environments.
What that means: Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments.
-
T1654 Log Enumeration Discovery
What they do: Akira _v2 can enumerate the trace, debug, error, info, and warning logs on targeted systems.
What that means: Adversaries may enumerate system and service logs to find useful data.
-
T1021.001 Remote Desktop Protocol Lateral Movement
What they do: Akira has used RDP for lateral movement.
What that means: Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP).
-
T1213.002 Sharepoint Collection
What they do: Akira has accessed and downloaded information stored in SharePoint instances as part of data gathering and exfiltration activity.
What that means: Adversaries may leverage the SharePoint repository as a source to mine valuable information.
-
T1560.001 Archive via Utility Collection
What they do: Akira uses utilities such as WinRAR to archive data prior to exfiltration.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1219 Remote Access Tools Command and Control
What they do: Akira uses legitimate utilities such as AnyDesk and PuTTy for maintaining remote access to victim environments.
What that means: An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: Akira will exfiltrate victim data using applications such as Rclone.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: Akira encrypts files in victim environments as part of ransomware operations.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Akira _v2 can stop running virtual machines.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Akira will delete system volume shadow copies via PowerShell commands.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1531 Account Access Removal Impact
What they do: Akira deletes administrator accounts in victim networks prior to encryption.
What that means: Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users.
-
T1657 Financial Theft Impact
What they do: Akira engages in double-extortion ransomware, exfiltrating files then encrypting them, in order to prompt victims to pay a ransom.
What that means: Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims.
Tools Observed (41)
▼Software Akira has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery
Discovery & enumeration
Exfiltration
Networking & tunnelling
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Crypto Wallets (15)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
bc1qr0pqfghr9cksfc5arr2rak3lt2y50v03pc76nh |
bitcoin | $997,461 | 2 |
bc1qfdzu6uv2nek524pe7lz4w0mxtt9898vfaegdaj |
bitcoin | $482,181 | 1 |
bc1q0dx45y82r5rt36sm38jv0k4dexwc4nj9z4ryw7 |
bitcoin | $446,073 | 2 |
bc1q9wnp6k7xxdqkdv4fa5ceyhv08espuskhu8ghq2 |
bitcoin | $351,883 | 1 |
bc1qknumj4326runqxfr58kg0s7v7gu9y5v5t9uv6h |
bitcoin | $298,537 | 2 |
bc1qr0txunr259we37wer7w6et33qyq0n6hv83pw24 |
bitcoin | $252,389 | 1 |
bc1q0lwpz2yufw3x9as6f679lwk8jx43g44683x5mc |
bitcoin | $229,395 | 4 |
bc1qhzd63mz9mfucak7yzfn65p6rcsgztnsqr3dak8 |
bitcoin | $150,205 | 1 |
bc1qqrsd02sqthm8gej8lfesgpx82saw7q2g5pjtah |
bitcoin | $149,891 | 1 |
bc1q4my6vqq8cg689drf9jccqudjclv67sz4cudkyd |
bitcoin | $139,534 | 1 |
bc1qpwwtck0zhzrj56fxeayz6wz5546nlp607qzpvh |
bitcoin | $109,655 | 2 |
bc1qghj85gz0dkr9jeucana3z4xu50ujtllj50rvj0 |
bitcoin | $106,115 | 2 |
+3 more wallets not shown (the 12 largest by amount received are listed).
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
akira_readme_3.txt
Hi friends, Whatever who you are and what your title is, if you're reading this it means the internal infrastructure of your company is fully or partially dead, all your backups - virtual, physical - everything that we managed to reach - are completely removed. Moreover, we have taken a great amount of your corporate data prior to encryption. ATTENTION! Strictly prohibited: - Deleting files with .arika extension; - Replacing or renaming .arika and .akira files; - Using third party software to recover your systems. If you violate these rules, we cannot guarantee a successful recovery. Well, for now let's keep all the tears and resentment to ourselves and try to build a constructive dialogue. We're fully aware of what damage we caused by locking your internal sources. At the moment, you have to know: 1. Dealing with us you will save A LOT due to we are not interested in ruining you financially. We will study in depth your finance, bank & income statements, your savings, investments etc. and present our reasonable demand to you. If you have an active cyber insurance, let us know and we will guide you how to properly use it. Also, dragging out the negotiation process will lead to failing of the deal. 2. Paying us you save your TIME, MONEY, EFFORTS and be back on track within 24 hours approximately. Our decryptor works properly on any files or systems, so you will be able to check it by requesting a test decryption service from the beginning of our conversation. If you decide to recover on your own, keep in mind that you can permanently lose access to some files or accidentally corrupt them - in this case we won't be able to help. 3. The security report or the exclusive first-hand information that you will receive upon reaching an agreement is of great value, since NO full audit of your network will show you the vulnerabilities that we've managed to detect and use in order to get into, identify backup solutions and download your data. 4. As for your data, if we fail to agree, we will try to sell personal information/trade secrets/databases/source codes - generally speaking, everything that has a value on the darkmarket - to multiple threat actors at once. Then all of this will be published in our blog - akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad[.]onion. 5. We're more than negotiable and will definitely find a way to settle this quickly and reach an agreement which will satisfy both of us. 6. Negotiations with Akira can only be conducted in a chat room, which you can access using the login details provided below or in the notes (a readme.txt file) in your systems. You should ignore any attempts (such as emails/social media messages, phone calls, etc.) to redirect you to another chat or email address (proton.me is often used by unauthorized individuals) on our behalf. 7. Be careful while working with recovery agencies as they often try to use your cyber incident to stuff their pockets. There are many risks for you to lose money and get nothing in return. If you're indeed interested in our assistance and the services we provide you can reach out to us following simple instructions: 1. Install TOR Browser to get access to our chat room - torproject[.]org/download/. 2. Paste this link - https://akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion/d/[snip] . 3. Use this code - [snip] - to log into our chat. Keep in mind that the faster you will get in touch, the less damage we cause.
akira_readme_2.txt
Hi friends, Whatever who you are and what your title is, if you're reading this it means the internal infrastructure of your company is fully or partially dead, all your backups - virtual, physical - everything that we managed to reach - are completely removed. Moreover, we have taken a great amount of your corporate data prior to encryption. ATTENTION! Strictly prohibited: - Deleting files with .arika extension; - Replacing or renaming .arika and .akira files; - Using third party software to recover your systems. If you violate these rules, we cannot guarantee a successful recovery. Well, for now let's keep all the tears and resentment to ourselves and try to build a constructive dialogue. We're fully aware of what damage we caused by locking your internal sources. At the moment, you have to know: 1. Dealing with us you will save A LOT due to we are not interested in ruining you financially. We will study in depth your finance, bank & income statements, your savings, investments etc. and present our reasonable demand to you. If you have an active cyber insurance, let us know and we will guide you how to properly use it. Also, dragging out the negotiation process will lead to failing of the deal. 2. Paying us you save your TIME, MONEY, EFFORTS and be back on track within 24 hours approximately. Our decryptor works properly on any files or systems, so you will be able to check it by requesting a test decryption service from the beginning of our conversation. If you decide to recover on your own, keep in mind that you can permanently lose access to some files or accidentally corrupt them - in this case we won't be able to help. 3. The security report or the exclusive first-hand information that you will receive upon reaching an agreement is of great value, since NO full audit of your network will show you the vulnerabilities that we've managed to detect and use in order to get into, identify backup solutions and download your data. 4. As for your data, if we fail to agree, we will try to sell personal information/trade secrets/databases/source codes - generally speaking, everything that has a value on the darkmarket - to multiple threat actors at once. Then all of this will be published in our blog - akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad[.]onion. 5. We're more than negotiable and will definitely find a way to settle this quickly and reach an agreement which will satisfy both of us. If you're indeed interested in our assistance and the services we provide you can reach out to us following simple instructions: 1. Install TOR Browser to get access to our chat room - torproject[.]org/download/. 2. Paste this link - https://akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion/d/[snip] . 3. Use this code - [snip] - to log into our chat. Keep in mind that the faster you will get in touch, the less damage we cause.
akira_readme.txt
Hi friends, Whatever who you are and what your title is if you're reading this it means the internal infrastructure of your company is fully or partially dead, all your backups - virtual, physical - everything that we managed to reach - are completely removed. Moreover, we have taken a great amount of your corporate data prior to encryption. Well, for now let's keep all the tears and resentment to ourselves and try to build a constructive dialogue. We're fully aware of what damage we caused by locking your internal sources. At the moment, you have to know: 1. Dealing with us you will save A LOT due to we are not interested in ruining your financially. We will study in depth your finance, bank & income statements, your savings, investments etc. and present our reasonable demand to you. If you have an active cyber insurance, let us know and we will guide you how to properly use it. Also, dragging out the negotiation process will lead to failing of a deal. 2. Paying us you save your TIME, MONEY, EFFORTS and be back on track within 24 hours approximately. Our decryptor works properly on any files or systems, so you will be able to check it by requesting a test decryption service from the beginning of our conversation. If you decide to recover on your own, keep in mind that you can permanently lose access to some files or accidently corrupt them - in this case we won't be able to help. 3. The security report or the exclusive first-hand information that you will receive upon reaching an agreement is of a great value, since NO full audit of your network will show you the vulnerabilities that we've managed to detect and used in order to get into, identify backup solutions and upload your data. 4. As for your data, if we fail to agree, we will try to sell personal information/trade secrets/databases/source codes - generally speaking, everything that has a value on the darkmarket - to multiple threat actors at ones. Then all of this will be published in our blog - https://akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion. 5. We're more than negotiable and will definitely find the way to settle this quickly and reach an agreement which will satisfy both of us. If you're indeed interested in our assistance and the services we provide you can reach out to us following simple instructions: 1. Install TOR Browser to get access to our chat room - https://www.torproject.org/download/. 2. Paste this link - https://akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id.onion. 3. Use this code - [snip] - to log into our chat. Keep in mind that the faster you will get in touch, the less damage we cause.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (1703)
Search, filter and paginate the victim timeline for Akira. Showing 1701–1703 of 1703.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Schottenstein Property Group Inc id6257 View details | Construction / Real Estate | — | pending | ||
|
Schottenstein Property Group Inc is a company operates in the Real Estate industry. The company interest in 80 retail properties in 23 states and corporate information of it's customers and that is now in our possession. Some of them are big and well-known. Personal information is also in this case. Schottenstein doesn't care much this data so you will be able to see it soon. |
||||||
| Ransomware | Thompson Builders id6256 View details | Construction / Real Estate | — | pending | ||
|
Thompson Builders is a part of a group of that are comprised of an entrepreneurial spirited under the leadership of Rob Thompson. They real estate, land development, design services, management & skilled trades; all under one roof. the same roof an accident has happened recently a good amount of corporate data of these went away from them. You have a unique chance to home for Thompson's corporate data (accounting, information, business contracts and much other including personal data of their employees). They be free soon! |
||||||
| Ransomware | Rockbridge Capital id6255 View details | Services | — | pending | ||
|
Rockbridge Capital is an investment adviser with the SEC and is headquartered in Columbus, Unfortunately, no one advised Rockbridge to in cyber security. This painful fact caused to lose much of business information: numerous contracts, projects, business contacts, detailed and personal employees information, confidential and so on and so forth. Almost 40 GB coming soon. |
||||||