Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Akira Ransomware

92
Global rank
85 infographic chevron month
Month rank
96 infographic chevron week
Week rank
0
IOCs

Akira Ransomware emerged in March 2023 and compromised over 250 organizations by January 2024 with approximately $42 million in ransom payments. It employs double extortion tactics exfiltrating data before encryption and threatening to publish it on a dedicated website.

Ransomware
Type
Unknown
Origin
1 March, 2023
First seen
9 September, 2026
Last seen

How to analyze Akira Ransomware with ANY.RUN

Type
Unknown
Origin
1 March, 2023
First seen
9 September, 2026
Last seen

IOCs

IP addresses
185.199.109.133
150.171.22.17
20.165.94.63
142.251.127.100
74.178.76.54
150.171.27.11
104.18.38.10
23.52.181.141
48.209.6.48
150.171.109.99
140.82.121.3
150.171.109.106
2.21.20.152
2.16.241.222
208.94.117.187
150.171.109.194
172.66.2.5
48.209.138.168
104.18.22.222
2.16.177.237
Hashes
99f3754dec345ed71e2bcb337e3cdc58b1a4c02d290d870dc20ccdd1ff543ae1
7497fbdbb98afca4ac455e3a057c59bcdebaf1280e25c94741dc301f05cb53e5
668c99e076dfb95e014829c4028460dee94a32b1fbb1c44116dffbf2dc48bf5b
7b9eb3a8af1d12da22604845995982ca99992876a825f3765e053ddb592620ab
1c99489111112d2150db0e18bbd474ff45f78fef80fa0e533dfd9ecfc6a3a480
eff52743773eb550fcc6ce3efc37c85724502233b6b002a35496d828bd7b280a
832f959ebb7ac959b337cb1ba8b40449a370167676a238782ec880ab9203aee0
8346cd7072d1b87fe75bbe71a996ed6593564eb39505b74457c5bbbf1cf43ae7
2e49845005576acc75d1fa54ca0aa29589c2714499a4d8d8122cb342b14ca446
365700061329b8191dec8517f0a4e08349d3ea315ab5daf0ca46c26f4d4b263c
ffe62e8d795a205f3ba5d9a4e14cb63949832b20af03562171251c2c7dc10c55
5dd3f6eb78e5342b781a03e6d518c2e5e2863d357a41b929d4f9295e7a8a9369
a6cdaf747032eec25fd454ffce3e4b24e039a8a7bfd955125f193b677256fcd3
e2b96ffd3615e5e6fd1c45b973e119c1482b0f1c42da90a64622ea776815df0f
bae18bd0703e2594fd6a573ce040fbd88585cbc7698c882570a9160329d4fee2
c378bfe2add2b67758655bc6d47b892584f52cfcf3f4453bf049112b7073672f
f0490ff9f946af11d7bdeeba36fd12e11b26b6b2fbc747bb0640461e93ae8263
b5c32238acba60d864f7b7584c00650427b4c4a53cc89b091679c8317d834b4f
f2c2098401fd859fb37623b9c981f9d8424549cd2c78cc1146dec746c8bd0b7a
0e8e5cc252b21336fbd765e139222103e534211b1a8fea0b01e20c60d8174601
Domains
static.edge.microsoftapp.net
client.wns.windows.com
silpyxehwplzmzqseyof.supabase.co
api.edgeoffer.microsoft.com
www.bing.com
edge-mobile-static.azureedge.net
fe3cr.delivery.mp.microsoft.com
settings-win.data.microsoft.com
config.edge.skype.com
msedge.b.tlu.dl.delivery.mp.microsoft.com
cosmicsky.xyz
edge.microsoft.com
www.microsoft.com
edge-cloud-resource-static.azureedge.net
go.microsoft.com
copilot.microsoft.com
login.live.com
ocsp.digicert.com
github.com
crl.microsoft.com
URLs
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:sfbp_fvru4r93mm0fykuh-o6r9ytyz8_6o0ofv4ohhi&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://silpyxehwplzmzqseyof.supabase.co/storage/v1/object/public/uploads/f7970491-0fcd-463b-aaa2-1e0ca3919ea1/proof_of_delivery_pod_351782_final_delivery_confirmation_document.exe
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://copilot.microsoft.com/c/api/user/eligibility
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d264%2526e%253d1
https://update.googleapis.com/service/update2/json?cup2key=14:21gz1qrtc-p9al-fjhp8rfloeyewuzktvcvmpi1dmjc&cup2hreq=17121e57050b0c30cda9322eb9b438e0cd68c2ad511c1f41badb68d3c0916c92
https://www.bing.com/api/shopping/v1/user/shoppingsettings?enabledservicefeaturesv2=edgeserverux.shopping.cashbackeumarkets,edgeserverux.shopping.msedgeshoppingcashbackdismisstimeout2s
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/fef489f0-c0aa-4886-ba2b-137e93d55624?p1=1789000080&p2=404&p3=2&p4=fh83izdzfxo6xwx%2bggtj7gdfb02uoxqxmb8pejfgl7g6aalx9fc1o4lifvuvbvwfi1auo2tknjeajm4k1oqrja%3d%3d
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/8f5fc415-8647-4b85-a913-4f863dae87ab?p1=1789000080&p2=404&p3=2&p4=bp9sjext6whm1lhtm0nsl3xsum8d2cijxrkr%2b6uap1eywj7a2m4lahetdkrzqirxamo5zli5sgvhqtpu3lgqsg%3d%3d
Last Seen at

Recent blog posts

post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 4780
comments 0
post image
15 Minutes Saved Per Alert: How a Lean German...
watchers 9604
comments 0
post image
HVNC Backdoor Targets LATAM Organizations wit...
watchers 11523
comments 0

What is Akira malware?

Akira is a ransomware-as-a-service that became known in the spring of 2023 as a weapon in the hands of Howling Scorpius group. Its ability to adapt, exploit vulnerabilities, and employ double-extortion tactics makes it a significant cybersecurity concern. That perception has been well-supported by hundreds of victims with ransom payments surpassing $40 mln.

It targets a spectrum of industries, including finance, technology, healthcare, education, and manufacturing. Being a human-operated ransomware, it can be manually adapted to bypass network defenses.

This ransomware uses a variety of methods to gain initial access to networks, often exploiting weaknesses in external-facing systems or human error. The methods include phishing, stolen credentials, VPN vulnerabilities, exploit kits and RMM tools.

Akira ransomware analysis in ANY.RUN Akira Ransomware ransom note shown inside ANY.RUN's Interactive Sandbox

Once inside the network, Akira conducts a multi-stage attack: first it creates scheduled tasks and registry keys to maintain access, deploys backdoors to allow re-entry. It spreads in the network and scans it for valuable data. It exfiltrates the data and then encrypts it on the endpoint adding an .akira file extension which is a reference to the 1988 Japanese anime "Akira". A ransom note with payment instructions is generated.

Akira is good at evasion: it abuses native Windows tools to execute payloads, leverages process injection and living-off-the-land techniques (LOLBins). Some components execute filelessly, directly in memory, reducing the footprint on disk.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Akira’s Prominent Features

Considering the basic TTPs, Akira is similar to most ransomware families, but it has a number of outstanding features that render it notably dangerous:

  • Akira is not industry specific though it prefers to target small and medium businesses.
  • Hackers actively manage the attack lifecycle. It grants Akira sophistication and adaptability, better evasion, longer dwell time and higher success rate
  • Akira can be quick and has been observed to move from initial access to information exfiltration in just two hours which is much faster than average.
  • Akira’s operators practice a "decryption proof" providing to build trust and pressure victims into paying the ransom.

Akira’s Execution Process and Technical Details

ANY.RUN's Interactive Sandbox allows to detonate Akira on virtual machine with set-up parameters while bypassing its sandbox evasion capabilities.

View sandbox analysis

The execution chain of Akira ransomware involves several key steps, from initial access to data encryption. Initially, Akira operators may gain entry through multiple methods, including exploiting VPNs without multi-factor authentication (MFA) and other known vulnerabilities. Once inside, they focus on privilege escalation and lateral movement.

Akira ransomware analysis in ANY.RUN Akira Ransomware analysis inside ANY.RUN's Interactive Sandbox

Post-infiltration, Akira uses tools like Advanced IP Scanner, MASSCAN, PCHunter, SharpHound, AdFind, and net Windows commands to map networks, identify critical systems, and gather domain information.

It uses credential-dumping tools (e.g., Mimikatz, LaZagne) to extract credentials from memory (LSASS) or browsers. In some cases, Akira extracts the NTDS.dit file from domain controllers by manipulating virtual machine (VM) backups, granting access to domain admin privileges.

To evade detection, Akira actors employ various defense evasion strategies. They may use tools such as PowerTool, KillAV, and Terminator to disable antivirus solutions. Registry modifications are performed to disable or reconfigure Microsoft Defender and to hide accounts on the login screen, ensuring their malicious activities remain undetected for as long as possible.

Akira ransomware analysis in ANY.RUN ANY.RUN highlights malicious activities performed by Akira Ransomware

In the final stages, attackers exfiltrate and encrypt data. Akira uses a combination of ChaCha20 and RSA encryption algorithms for secure data encryption. Files are renamed with the .akira extension, and a ransom note is left behind. PowerShell commands are executed to delete Volume Shadow Copy Service (VSS) files—preventing easy file recovery.

In one observed instance, a PowerShell process (PID 5008) deleted these VSS files. Data is also compressed (using tools like WinRAR, FileZilla, WinSCP, Rclone) and exfiltrated, often camouflaged as legitimate traffic to avoid detection.

After encrypting and exfiltrating data, Akira places ransom notes, such as akira_readme.txt, in various directories. These notes provide instructions for victims to recover their encrypted files by paying a ransom. The ransom demand marks the culmination of the attack, as the attackers attempt to extort payment in exchange for the decryption key.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Gathering threat intelligence on Akira malware

Akira continues to steadily spread and to result in more victims calling for special attention by SOC teams for timely prevention and response. Use Threat Intelligence Lookup to track IOCs like C2 domains, hashes, and known IPs related to Akira; apply YARA rules to identify malicious binaries and scripts.

Akira ransomware results in ANY.RUN TI Lookup TI Lookup helps users collect fresh intel on Akira Ransomware attacks

With the use of the query threatName:"akira", we can identify the latest samples of this ransomware and collect fresh intel.

TI Lookup provides a list of recent sandbox sessions featuring analysis of Akira Ransomware. You can explore each of these in more detail and export the findings in JSON.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Akira RaaS has emerged as a significant threat in the landscape because it enables even low-skilled actors to deploy highly sophisticated ransomware attacks and operates encryptors for Windows and Linux operating systems. Organizations should secure their perimeter and ensure proactive defense against this threat by employing threat intelligence tools like TI Lookup to gather the latest IOCs.

Get 50 requests in TI Lookup to collect fresh threat intelligence on Akira and other malware and phishing attacks

HAVE A LOOK AT

Phorpiex screenshot
Phorpiex
phorpiex
Phorpiex is a malicious software that has been a significant threat in the cybersecurity landscape since 2016. It is a modular malware known for its ability to maintain an extensive botnet. Unlike other botnets, Phorpiex does not concentrate on DDoS attacks. Instead, it has been involved in numerous large-scale spam email campaigns and the distribution of other malicious payloads, such as LockBit.
Read More
Remcos screenshot
Remcos is a commercially distributed remote administration and surveillance tool that has been widely observed in unauthorized deployments, where threat actors use it to perform remote actions on compromised machines. It is actively maintained by its vendor, with new versions and feature updates released on a frequent, near-monthly basis.
Read More
ClickLock screenshot
ClickLock
clicklock
ClickLock is a macOS information stealer and remote backdoor distributed via deceptive, terminal-based social engineering pages. Once executed, it bypasses Gatekeeper checks by stripping download quarantine flags and signing its executable with ad-hoc digital certificates. If users resist its initial demands, the malware initiates high-frequency background loops that repeatedly kill vital operating system applications to force plaintext password entry. It exfiltrates captured browser data, system keychain credentials, and cryptocurrency wallets to a Telegram bot before establishing a permanent backdoor.
Read More
Kali365 screenshot
Kali365 is an emerging Phishing-as-a-Service (PhaaS) platform that targets Microsoft 365 environments by stealing OAuth authentication tokens instead of passwords. First observed in April 2026, the service enables even low-skilled threat actors to bypass multi-factor authentication (MFA), gain persistent access to corporate cloud accounts, and compromise business communications, files, and collaboration platforms. Kali365 represents a shift from traditional credential theft toward session hijacking and token abuse, making it a significant threat to organizations that rely on Microsoft 365.
Read More
DarkVision screenshot
DarkVision
darkvision
DarkVision RAT is a low-cost, modular Remote Access Trojan that gives attackers remote control of infected Windows hosts. Initially observed around 2020 and sold in underground marketplaces, DarkVision has become notable for its full feature set (keylogging, screen capture, file theft, remote command execution and plugin support) and for being distributed via multi-stage loaders in recent campaigns.
Read More
GravityRAT screenshot
GravityRAT
gravity
GravityRAT is a sophisticated spyware and remote access trojan that has been actively targeting organizations and government entities since 2016. It uses innovative anti-analysis techniques and made an evolution from a Windows-only threat to a cross-platform espionage tool capable of compromising Windows, Android, and macOS systems.
Read More