Threat group.View on attack.mitre.org
Akira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.
| Technique | Procedure example |
|---|---|
| T1018 Remote System Discovery |
Akira uses software such as Advanced IP Scanner and MASSCAN to identify remote hosts within victim networks. |
| T1021.001 Remote Desktop Protocol |
Akira has used RDP for lateral movement. |
| T1027.001 Binary Padding |
Akira has used binary padding to obfuscate payloads. |
| T1036.005 Match Legitimate Resource Name or Location |
Akira has used legitimate names and locations for files to evade defenses. |
| T1059.001 PowerShell |
Akira has used PowerShell scripts for credential harvesting and privilege escalation. |
| T1078 Valid Accounts |
Akira uses valid account information to remotely access victim networks, such as VPN credentials. |
| T1133 External Remote Services |
Akira uses compromised VPN accounts for initial access to victim networks. |
| T1213.002 Sharepoint |
Akira has accessed and downloaded information stored in SharePoint instances as part of data gathering and exfiltration activity. |
| T1219 Remote Access Tools |
Akira uses legitimate utilities such as AnyDesk and PuTTy for maintaining remote access to victim environments. |
| T1482 Domain Trust Discovery |
Akira uses the built-in Nltest utility or tools such as AdFind to enumerate Active Directory trusts in victim environments. |
| T1486 Data Encrypted for Impact |
Akira encrypts files in victim environments as part of ransomware operations. |
| T1531 Account Access Removal |
Akira deletes administrator accounts in victim networks prior to encryption. |
| T1558 Steal or Forge Kerberos Tickets |
Akira have used scripts to dump Kerberos authentication credentials. |
| T1560.001 Archive via Utility |
Akira uses utilities such as WinRAR to archive data prior to exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
Akira will exfiltrate victim data using applications such as Rclone. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.