← Back to all threat actors

Akira

Also known as GOLD SAHARA, PUNK SPIDER, Howling Scorpius, Storm-1567
Tracked as G1024

Akira is a financially motivated ransomware-as-a-service operation active since March 2023. It uses credential abuse, remote services, phishing, and exploitation of internet-facing infrastructure before credential theft, lateral movement, data exfiltration, and encryption. Its Windows and Linux-family payloads have expanded from VMware ESXi to Hyper-V and Nutanix AHV environments.

How we source and review actor profiles
Motivation
ransomware
Sectors
manufacturing, education, technology, healthcare, financial-services, food-agriculture
Status
Active

Threat intelligence assessment

At a glance

A mature extortion operation that couples edge-device access and credential abuse with cross-hypervisor encryption and cloud-assisted data theft.

Actor class
Ransomware-as-a-service operation
Motivation
Financial

Facts

  • Akira primarily targets small and medium-sized businesses but has also impacted large organizations and critical infrastructure.
  • The November 2025 joint advisory associates Akira with Storm-1567, Howling Scorpius, PUNK SPIDER, and GOLD SAHARA.
  • The advisory reports possible connections to the defunct Conti ransomware group without treating Conti as an alias.

Activity timeline

First observed
March 2023
Status
Active
Status as of
2025-11-13

Facts

  • A Linux variant targeting VMware ESXi appeared in April 2023 after an initial Windows focus.
  • A June 2025 incident expanded observed encryption to Nutanix AHV virtual-machine disks.
  • The joint advisory reports approximately $244.17 million in ransomware proceeds as of late September 2025.

Attribution assessment

Facts

  • Government and vendor tracking names are preserved as source names for the same Akira operation.
  • A possible connection to Conti is an assessment and is not represented as an exact identity match.

Operational playbook

Stages

  • Access VPN, RDP, backup, firewall, or other internet-facing services through stolen credentials, phishing, brute force, or vulnerability exploitation.
  • Create local or domain accounts and gather credentials through Kerberoasting, LSASS access, registry-hive theft, browser data, and credential-dumping tools.
  • Enumerate hosts, network configuration, domain trusts, accounts, groups, files, and virtualization infrastructure.
  • Disable security products and establish remote control or tunnels with common administration tools.
  • Archive and exfiltrate data through FTP, SFTP, cloud storage, and file-transfer tools.
  • Encrypt Windows and virtualization workloads, inhibit recovery, and direct the victim to a Tor negotiation site.

Initial access and identity targets

Methods

  • VPN access without MFA and abuse of valid credentials
  • RDP and other external remote services
  • Spearphishing attachments and links
  • Credential stuffing and brute force
  • Exploitation of Cisco, SonicWall, VMware, Veeam, and other internet-facing products

Capabilities and evasion

Facts

  • Akira, Megazord, and Akira_v2 variants cover Windows, Linux, VMware ESXi, Hyper-V, and Nutanix AHV targets.
  • Early C++ variants used the .akira extension; Rust-based Megazord variants used .powerranges.
  • Observed tradecraft includes BYOVD defense impairment, PowerShell, WMI, PsExec, credential dumping, shadow-copy deletion, and intermittent encryption.
  • Remote access and tunneling have included AnyDesk, MobaXterm, RustDesk, Ngrok, Cloudflare Tunnel, and OpenSSH.

Infrastructure patterns

Facts

  • Victim-specific codes in ransom notes direct affected organizations to a Tor-hosted negotiation service.
  • Akira has used commodity remote-management, tunneling, FTP, SFTP, and cloud-storage services, which require behavioral context before blocking.

Communication and pressure channels

Channels

  • Victim-specific ransom note
  • Tor negotiation site
  • Data-leak site

Observed targeting

Targeting, not victimization. Sector and regional patterns describe observed impact and targeting. Individual leak-site listings remain claims unless independently confirmed.

Facts

  • Observed regions include North America, Europe, and Australia.
  • Preferred sectors include manufacturing, education, information technology, healthcare and public health, financial services, and food and agriculture.

Defender guidance

Measures

  • Prioritize remediation of known exploited vulnerabilities on internet-facing firewalls, VPNs, virtualization platforms, and backup servers.
  • Require phishing-resistant MFA for remote access and administrative accounts.
  • Hunt for unexpected local or domain account creation, RDP or VPN logins, credential-dumping activity, and remote-management tools.
  • Restrict and monitor Rclone, WinSCP, FileZilla, Ngrok, Cloudflare Tunnel, and similar transfer or tunneling utilities.
  • Maintain offline backups and regularly test restoration across virtualization and identity dependencies.

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityTracking identifier: G1024

Reviewed identity mapping approved on this date.

Claimed
Victim claimAK Stamping listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimEagle Construction listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimGeorge Cameron Nash listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimKyodo USA listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimBrent Electric listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimBrentwood Country Club listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimCreateASoft listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimStransky Heiz-Mess-Regeltechnik GmbH listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimWorrell listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimScrubaDub Auto Wash Centers listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimAlgra Group listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimCongressional Iron Works listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimFlex1 listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimKFZ-MEISTERBETRIEB JOST GmbH listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimWEMS listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimAlumax listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimBEPeterson listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimJRT Mechanical listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimCGP MEP listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimGill Rock Drill listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimOral and Maxillofacial Surgery listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimPA-ID listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimWINTER Ingenieure listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimBihl listed by Akira

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed

The interactive view includes 109 dated events with category filters and paging.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

AkiraCanonical Name
GOLD SAHARAAlias
Howling ScorpiusAlias
PUNK SPIDERAlias
G1024Tracking Id
Storm-1567Alias

Loading CVEs, techniques, indicators, malware, victims, and activity...