Akira
Also known as: gold sahara, howling scorpius, megazord, punk spider
Profile
Akira is an affiliate-operated ransomware family that combines system encryption with prior data theft to pressure victims (double extortion). Its operators gain access mainly in two ways: abusing corporate remote access (credential spraying against SonicWall SSL VPN without MFA, followed by RDP use) and distributing trojanized installers of legitimate software, such as a fake ManageEngine OpManager installer promoted through SEO poisoning. A documented July 2025 intrusion shows a fast chain: initial access with the BumbleBee loader, command and control via AdaptixC2, lateral movement, credential dumping and exfiltration, with ransomware deployed in roughly 44 hours. Affiliates rely on legitimate and administrative tooling to stay under the radar, and have even attempted to reboot machines into Safe Mode to disable EDR, a tactic that in at least one case caused the encryption to fail. Victim selection appears opportunistic rather than sector-specific; incidents have been observed involving victims in Ukraine.
Initial access
- Credential spraying against SonicWall SSL VPN without MFA
- RDP abuse with valid credentials
- SEO poisoning
- Trojanized ManageEngine OpManager installer
Tools
BumbleBee (loader), AdaptixC2 (command and control), RustDesk (remote access), FileZilla (exfiltration), s5cmd (cloud storage transfer), lsassy (credential dumping), wbadmin.exe, bcdedit, msconfig.exe
What defenders should watch
- Enforce MFA on all VPN access (especially SonicWall SSL VPN) and on RDP, apply account lockouts, and alert on bursts of failed authentications typical of credential spraying.
- Monitor and alert on bcdedit and msconfig.exe usage to configure Safe Mode boots: this is used to disable EDR before encryption.
- Watch wbadmin.exe and any deletion of backups or shadow copies; keep offline, immutable backups outside the domain.
- Detect unauthorized exfiltration and remote access tooling (FileZilla, s5cmd, RustDesk) and restrict execution via allow-listing.
- Control downloads of administration software (e.g. ManageEngine OpManager) by mandating official sources and signature verification, given the use of trojanized installers spread via SEO poisoning.
- Dwell time between initial access and encryption can be under 48 hours: prioritize early detection of credential dumping (lsassy, LSASS access) and C2 traffic.
Most affected countries
- United States49
- Germany5
- Brazil2
- Canada2
- United Kingdom1
- Italy1
- Norway1
- Slovenia1
Most affected sectors
- Manufacturing17
- Construction15
- Professional services11
- Technology6
- Retail4
- Legal4
- Agriculture & food4
- Real estate4
Priority mitigations
MITRE ATT&CK mitigations that cover the most techniques used by this group.
- Audit (6 techniques covered)
- User Account Management (5 techniques covered)
- Disable or Remove Feature or Program (5 techniques covered)
- Privileged Account Management (4 techniques covered)
- Execution Prevention (4 techniques covered)
- User Training (3 techniques covered)
- Network Segmentation (3 techniques covered)
- Multi-factor Authentication (3 techniques covered)
MITRE ATT&CK techniques
Recent victims
| Organisation | Country | Sector | Claimed | Status |
|---|---|---|---|---|
| Knit | — | Professional services | 9/28/2026 | ◌ Claimed (unverified) |
| Geebee Garments | — | Manufacturing | 9/28/2026 | ◌ Claimed (unverified) |
| Strack Companies | United States | Construction | 9/24/2026 | ◌ Claimed (unverified) |
| Wallatec | — | Manufacturing | 9/24/2026 | ◌ Claimed (unverified) |
| Apex Litigation Support | United States | Legal | 9/23/2026 | ◌ Claimed (unverified) |
| Urban Engineering | United States | Professional services | 9/23/2026 | ◌ Claimed (unverified) |
| HIT | Slovenia | Hospitality & tourism | 9/23/2026 | ◌ Claimed (unverified) |
| DI.C.S.EL. S.R.L. | Italy | Technology | 9/22/2026 | ◌ Claimed (unverified) |
| Coe Press Equipment | — | Manufacturing | 9/22/2026 | ◌ Claimed (unverified) |
| TDMI | — | Manufacturing | 9/22/2026 | ◌ Claimed (unverified) |
| Prestige Management Inc. | United States | Real estate | 9/21/2026 | ◌ Claimed (unverified) |
| Anderson Industries | — | Manufacturing | 9/18/2026 | ◌ Claimed (unverified) |
| Vetta Digital Serviços | Brazil | Energy & utilities | 9/17/2026 | ◌ Claimed (unverified) |
| Javep Chevrolet | — | Automotive | 9/17/2026 | ◌ Claimed (unverified) |
| Practice Management | — | Healthcare | 9/17/2026 | ◌ Claimed (unverified) |
| Manders | United States | Construction | 9/16/2026 | ◌ Claimed (unverified) |
| Blossomland Accounting | United States | Professional services | 9/16/2026 | ◌ Claimed (unverified) |
| Bee Maid Honey Limited | Canada | Agriculture & food | 9/16/2026 | ◌ Claimed (unverified) |
| Southern California Telephone Company | United States | Telecommunications | 9/15/2026 | ◌ Claimed (unverified) |
| Lazy Boyz Harley-Davidson Oslo | Norway | Automotive | 9/15/2026 | ◌ Claimed (unverified) |
| Pilot Precision Products | — | Manufacturing | 9/15/2026 | ◌ Claimed (unverified) |
| AK Stamping | — | Manufacturing | 9/10/2026 | ◌ Claimed (unverified) |
| Eagle Construction | United States | Construction | 9/10/2026 | ◌ Claimed (unverified) |
| 🔒 Profesional del diseño de interiores (US) | United States | Retail | 9/10/2026 | ◌ Claimed (unverified) |
| Kyodo USA | United States | Transport & logistics | 9/9/2026 | ◌ Claimed (unverified) |
Sources analysed
- Akira Affiliate Crashes Ransomware After Attempting EDR Evasion (Infosecurity Magazine, 8/13/2026)
- From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira (The DFIR Report, 6/29/2026)
Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.
Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, GDELT.