Akira Group
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Akira Group is a ransomware threat actor known by the alias Akira Group. The actor is reported to be based in Singapore. It first appeared in public reports in early 2023. The group operates under the Akira moniker in underground forums and malware repositories. Its emergence was noted by multiple cybersecurity firms tracking ransomware trends.
Akira Group primarily targets organizations across various sectors including education, healthcare, finance, and manufacturing. Victims have been reported in North America, Europe, and Asia. The actor's strategic objective is financial gain achieved through ransomware encryption and data extortion. They employ a double extortion model, threatening to leak stolen data if the ransom is not paid. This approach aligns with the broader trend of ransomware groups seeking both payment and reputational pressure.
Initial access for Akira Group often involves exploitation of vulnerable virtual private network (VPN) appliances and remote desktop services. Once inside, the group deploys a custom ransomware variant that encrypts files on both Windows and Linux systems. Their toolkit includes legitimate administration tools such as Cobalt Strike for lateral movement and Mimikatz for credential harvesting. The group also utilizes living-off-the-land binaries to evade detection while moving laterally within victim networks. These TTPs have been observed in multiple incident response reports linking the activity to the Akira alias.
Incidents
Attributed incidents are available to members.
0 incidents