Akira

S1129

Malware.View on attack.mitre.org

About this malware

Akira ransomware, written in C++, is most prominently (but not exclusively) associated with the ransomware-as-a-service entity Akira. Akira ransomware has been used in attacks across North America, Europe, and Australia, with a focus on critical infrastructure sectors including manufacturing, education, and IT services. Akira ransomware employs hybrid encryption and threading to increase the speed and efficiency of encryption and runtime arguments for tailored attacks. Notable variants include Rust-based Megazord for targeting Windows and Akira _v2 for targeting VMware ESXi servers.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1047
Windows Management Instrumentation

Akira will leverage COM objects accessed through WMI during execution to evade detection.

T1057
Process Discovery

Akira verifies the deletion of volume shadow copies by checking for the existence of the process ID related to the process created to delete these items.

T1059.001
PowerShell

Akira will execute PowerShell commands to delete system volume shadow copies.

T1059.003
Windows Command Shell

Akira executes from the Windows command line and can take various arguments for execution.

T1082
System Information Discovery

Akira uses the GetSystemInfo Windows function to determine the number of processors on a victim machine.

T1083
File and Directory Discovery

Akira examines files prior to encryption to determine if they meet requirements for encryption and can be encrypted by the ransomware. These checks are performed through native Windows functions such as GetFileAttributesW.

T1106
Native API

Akira executes native Windows functions such as GetFileAttributesW and `GetSystemInfo`.

T1135
Network Share Discovery

Akira can identify remote file shares for encryption.

T1486
Data Encrypted for Impact

Akira can encrypt victim filesystems for financial extortion purposes including through the use of the ChaCha20 and ChaCha8 stream ciphers.

T1490
Inhibit System Recovery

Akira will delete system volume shadow copies via PowerShell commands.

Groups that use it1

Campaigns0

None recorded.

References3

  1. CISA Akira Ransomware APR 2024 Open source
    CISA et al. (2024, April 18). #StopRansomware: Akira Ransomware. Retrieved December 10, 2024.
  2. Cisco Akira Ransomware OCT 2024 Open source
    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.
  3. Kersten Akira 2023 Open source
    Max Kersten & Alexandre Mundo. (2023, November 29). Akira Ransomware. Retrieved April 4, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.