Ransomware Group intelligence
Ako
ActiveTrack Ako with 0 published victims and 1 known leak locations in a single intelligence view.
Overview
Ako is tracked by Breach House as a ransomware group with 0 published victims.
The group is tracked across multiple victim records in the Breach House dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 8h ago | kwvhrdibgmmpkhkidrby4mccwqpds5za6uo2thcw5gz75qncv7rbhyad.onion |
Top Activity Sectors
No sector intelligence available.
Typical Attacks (7)
▼MITRE ATT&CK does not currently catalogue Ako, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: low. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: ako uses PowerShell scripts to execute malicious commands and deploy payloads across the network.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: ako disables security tools and event log collectors to hinder incident response and detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: ako deletes Volume Shadow Copies and backup directories to prevent recovery from ransomware encryption.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1135 Network Share Discovery Discovery
What they do: ako scans network shares to discover victim systems and identify files suitable for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: ako exfiltrates stolen data via encrypted C2 channels before demanding payment.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: ako encrypts victim files using strong symmetric cryptography to hold data for ransom.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: ako runs system recovery inhibitors to block automated remediation and restore processes.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Crypto Wallets (1)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
1DUBrMcH9T13oFSa59jxtFDM5eWTP8v2yc |
bitcoin | $33,442 | 12 |
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
ako-readme.txt
--- We apologize! --- Your network have been locked. ------------------------------ | Whats happened? ------------------------------ All your files, documents, photos, databases and other important data are encrypted and have the extension: .jD4955 Backups and shadow copies also encrypted or removed. Any third-party software may damage encrypted data but not recover. From this moment, it will be impossible to use files until they are decrypted. The only method of recovering files is to purchase an unique private key. Only we can give you this key and only we can recovery your files. ------------------------------ | Guarantees? ------------------------------ As you read above, files can be decrypted only using our private key and a special program. The only guarantees we can give are decryption of your any file. So you can decrypt any file from your system for free on our website. We guarantee that you can recovery all your files. But you have not so enough time. ------------------------------ | How to recovery my files? ------------------------------ To get info (decrypt your files) you have 1 way: 1) [Recommended] via Tor Browser: a) Download and install Tor Browser: https://www.torproject.org/download/ b) Open our website in TOR: http://kwvhrdibgmmpkhkidrby4mccwqpds5za6uo2thcw5gz75qncv7rbhyad.onion/[snip] When you open our website, put the following key in the input form: [snip] !! ATTENTION !! !! Any third - party software may damage encrypted data but not recover. !! !! DO NOT MODIFY ENCRYPTED FILES !! !! DO NOT CHANGE YOUR ID !! !! DO NOT REMOVE YOUR ID.KEY FILE !!
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (0)
Search, filter and paginate the victim timeline for Ako.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|