Ransomware Ransomware-as-a-Service (Conti Lineage) Active since 2023

Akira Ransomware

$42M+ damages across 250+ victims. Targets VPN appliances. Linux/VMware ESXi variants.

Scroll

Akira is a ransomware-as-a-service operation active since March 2023 with confirmed ties to the former Conti ransomware group. The operation has caused over $42 million in damages across 250+ organizations, primarily gaining initial access through Cisco AnyConnect VPN vulnerabilities and compromised VPN credentials.

AttributeDetail
NamesAkira Ransomware
AttributionRansomware-as-a-Service (Conti Lineage)
Active Since2023
Primary Focus$42M+ damages across 250+ victims. Targets VPN appliances. Linux/VMware ESXi variants.

Overview

Akira is a ransomware-as-a-service operation active since March 2023 with confirmed ties to the former Conti ransomware group. The operation has caused over $42 million in damages across 250+ organizations, primarily gaining initial access through Cisco AnyConnect VPN vulnerabilities and compromised VPN credentials.

Attribution

Akira Ransomware is attributed to Ransomware-as-a-Service (Conti Lineage), active since at least 2023. $42M+ damages across 250+ victims. Targets VPN appliances. Linux/VMware ESXi variants.

Notable Campaigns

MITRE ATT&CK Mapping

Technique IDTechniqueConfidence
T1133External Remote ServicesHigh
T1486Data Encrypted for ImpactHigh
T1490Inhibit System RecoveryHigh
T1059Command and Scripting InterpreterHigh
T1048Exfiltration Over Alternative ProtocolHigh

Detection & Defense

Recommended Defenses

Monitor for the TTPs listed above using your SIEM and EDR platforms. Prioritize patching of internet-facing applications and enforce MFA on all remote access. Mjolnir Security provides continuous threat hunting and monitoring for Akira activity patterns.

Mjolnir Security — Threat Intelligence & Response

Mjolnir Security provides 24/7 threat monitoring, incident response, and threat intelligence services. Contact us for threat hunting specifically targeting Akira TTPs in your environment.

Threat Hunting Incident Response Threat Intelligence SOC-as-a-Service

mjolnirsecurity.com — 24/7 Incident Response Hotline: +1 833 403 5875