AKO
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
AKO is a ransomware threat actor also known by the alias Ako, with publicly available information indicating an operational base in Russia. The actor’s primary objective appears to be financial gain, as demonstrated by ransom demands for decryption keys and additional payments to prevent the release of exfiltrated data. Observed victims span multiple sectors, including medical practices, various business entities, and a K‑12 school district, with attacks affecting organizations both inside and outside the United States.
AKO employs a double extortion tactic, first stealing sensitive data before encrypting the victim’s systems with its ransomware. The actor maintains a Tor‑hosted leak site where it publishes samples of stolen information and threatens broader disclosure unless payment is received. Victims are presented with two separate fees: one for obtaining a decryption key and another for the deletion of the exfiltrated files, a model explicitly referenced in the actor’s communications. The ransomware itself encrypts files after data exfiltration, and the leaked material often consists of PDFs, scanned documents, and other non‑database formats containing personally identifiable information.
A representative campaign occurred on May 13 2020, when AKO targeted a Massachusetts‑based pain management practice, exfiltrating over four gigabytes of protected health information and demanding $350 000 for decryption while threatening further leaks. The actor’s Tor site at the time listed additional victims from the medical, business, and education sectors, illustrating a pattern of targeting diverse organizations to maximize extortion pressure. These observed activities constitute the publicly documented scope of AKO’s operations.
Incidents
Attributed incidents are available to members.
1 incident