« All threats

APT groupMITRE G1024

Akira

Also known as: gold sahara, howling scorpius, megazord, punk spider

Profile

Akira is an affiliate-operated ransomware family that combines system encryption with prior data theft to pressure victims (double extortion). Its operators gain access mainly in two ways: abusing corporate remote access (credential spraying against SonicWall SSL VPN without MFA, followed by RDP use) and distributing trojanized installers of legitimate software, such as a fake ManageEngine OpManager installer promoted through SEO poisoning. A documented July 2025 intrusion shows a fast chain: initial access with the BumbleBee loader, command and control via AdaptixC2, lateral movement, credential dumping and exfiltration, with ransomware deployed in roughly 44 hours. Affiliates rely on legitimate and administrative tooling to stay under the radar, and have even attempted to reboot machines into Safe Mode to disable EDR, a tactic that in at least one case caused the encryption to fail. Victim selection appears opportunistic rather than sector-specific; incidents have been observed involving victims in Ukraine.

Initial access

Tools

BumbleBee (loader), AdaptixC2 (command and control), RustDesk (remote access), FileZilla (exfiltration), s5cmd (cloud storage transfer), lsassy (credential dumping), wbadmin.exe, bcdedit, msconfig.exe

What defenders should watch

Victims in the last 90 days87

Most affected countries

  1. United States49
  2. Germany5
  3. Brazil2
  4. Canada2
  5. United Kingdom1
  6. Italy1
  7. Norway1
  8. Slovenia1

Most affected sectors

  1. Manufacturing17
  2. Construction15
  3. Professional services11
  4. Technology6
  5. Retail4
  6. Legal4
  7. Agriculture & food4
  8. Real estate4

Priority mitigations

MITRE ATT&CK mitigations that cover the most techniques used by this group.

  1. Audit (6 techniques covered)
  2. User Account Management (5 techniques covered)
  3. Disable or Remove Feature or Program (5 techniques covered)
  4. Privileged Account Management (4 techniques covered)
  5. Execution Prevention (4 techniques covered)
  6. User Training (3 techniques covered)
  7. Network Segmentation (3 techniques covered)
  8. Multi-factor Authentication (3 techniques covered)

MITRE ATT&CK techniques

Recent victims

OrganisationCountrySectorClaimedStatus
Knit—Professional services9/28/2026◌ Claimed (unverified)
Geebee Garments—Manufacturing9/28/2026◌ Claimed (unverified)
Strack CompaniesUnited StatesConstruction9/24/2026◌ Claimed (unverified)
Wallatec—Manufacturing9/24/2026◌ Claimed (unverified)
Apex Litigation SupportUnited StatesLegal9/23/2026◌ Claimed (unverified)
Urban EngineeringUnited StatesProfessional services9/23/2026◌ Claimed (unverified)
HITSloveniaHospitality & tourism9/23/2026◌ Claimed (unverified)
DI.C.S.EL. S.R.L.ItalyTechnology9/22/2026◌ Claimed (unverified)
Coe Press Equipment—Manufacturing9/22/2026◌ Claimed (unverified)
TDMI—Manufacturing9/22/2026◌ Claimed (unverified)
Prestige Management Inc.United StatesReal estate9/21/2026◌ Claimed (unverified)
Anderson Industries—Manufacturing9/18/2026◌ Claimed (unverified)
Vetta Digital ServiçosBrazilEnergy & utilities9/17/2026◌ Claimed (unverified)
Javep Chevrolet—Automotive9/17/2026◌ Claimed (unverified)
Practice Management—Healthcare9/17/2026◌ Claimed (unverified)
MandersUnited StatesConstruction9/16/2026◌ Claimed (unverified)
Blossomland AccountingUnited StatesProfessional services9/16/2026◌ Claimed (unverified)
Bee Maid Honey LimitedCanadaAgriculture & food9/16/2026◌ Claimed (unverified)
Southern California Telephone CompanyUnited StatesTelecommunications9/15/2026◌ Claimed (unverified)
Lazy Boyz Harley-Davidson OsloNorwayAutomotive9/15/2026◌ Claimed (unverified)
Pilot Precision Products—Manufacturing9/15/2026◌ Claimed (unverified)
AK Stamping—Manufacturing9/10/2026◌ Claimed (unverified)
Eagle ConstructionUnited StatesConstruction9/10/2026◌ Claimed (unverified)
🔒 Profesional del diseño de interiores (US)United StatesRetail9/10/2026◌ Claimed (unverified)
Kyodo USAUnited StatesTransport & logistics9/9/2026◌ Claimed (unverified)

Sources analysed

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, GDELT.