๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

What is Akira ransomware

What is Akira ransomware?

Akira is a ransomware group active since 2023 that has hit hundreds of organisations across North America, Europe, and Australia, with a particular focus on small-to-medium businesses, healthcare practices, and accounting firms. It runs as a ransomware-as-a-service operation with affiliates doing many of the intrusions.

Start free, no credit card See the attack chain

RaaS · VPN and credential access · backup destruction · double extortion

Definition

Akira emerged in March 2023 and has grown rapidly. The group operates as a ransomware-as-a-service (RaaS) operation with affiliates conducting many of the actual intrusions. Targeting patterns favour small-to-medium organisations that are likely to pay ransom rather than face prolonged downtime.

Initial access patterns documented in Akira incidents include unpatched Cisco ASA and Cisco AnyConnect VPN appliances, credential-stuffing against VPN portals lacking MFA, and, increasingly, phishing combined with M365 and Entra ID compromise.

Post-compromise behaviour includes Mimikatz-class credential dumping, ADRecon and SoftPerfect Network Scanner reconnaissance, lateral movement via PsExec, WMI, and RDP, deletion of Volume Shadow Copies, and targeting of backup systems before deploying encryption. Encryption uses ChaCha20 with RSA-protected keys, and encrypted files receive a .akira extension.

Healthcare practices, accounting firms, and small manufacturers are over-represented in Akira victim lists. Canadian healthcare and accounting firms specifically have appeared multiple times in 2024 to 2026.

Core components

Initial access vectors

Unpatched Cisco ASA and AnyConnect VPN, credential stuffing without MFA, and phishing into M365.

Reconnaissance and credential dumping

Mimikatz-class tooling, ADRecon, SoftPerfect Network Scanner, net.exe, and whoami.exe with privileged context.

Lateral movement

PsExec, WMI, Remote Desktop, and exploitation of cached credentials.

Backup destruction

Targeted deletion of Volume Shadow Copies and tampering with backup systems prior to encryption.

Encryption

ChaCha20 with RSA-protected keys, and a .akira file extension.

Double extortion

Data exfiltration before encryption. The ransom demand combines a decryption fee with the threat of data publication on the Akira leak site.

Why it matters

Akira specifically targets organisations of the size most MSPs serve. SMBs, healthcare practices, accounting firms, and small manufacturers are in the wheelhouse. They have valuable data, cannot absorb prolonged downtime, and may not have mature security programs.

For MSPs, an Akira incident is a worst-case scenario. The customer's network is encrypted, backups may be destroyed, decryption is uncertain, and the regulatory consequences (HIPAA breach notification, PIPEDA, Alberta HIA and BC HIA notification, state privacy laws) follow even if the ransom is paid.

The valuable detection window is the staging phase, meaning reconnaissance, credential dumping, lateral movement, and backup tampering, not the encryption itself. By encryption, it is far too late.

How Lavawall® helps with Akira ransomware

Lavawall® includes a dedicated Akira ransomware indicator hunter that matches against known Akira tooling, file paths, registry keys, and behaviour patterns observed in actual Akira incident response. Detection runs continuously across Windows, macOS, and Linux endpoints.

Behavioural staging detection covers Mimikatz-class credential dumping, reconnaissance commands (net.exe, whoami.exe, ADRecon-class activity), lateral movement (PsExec-class activity), and backup-destruction attempts. The aim is detection during staging, not after encryption.

Multi-tenant ITDR correlates endpoint signals with M365 and Entra ID activity to catch the credential-phishing-then-pivot pattern Akira increasingly uses. Configuration assessment surfaces the unpatched Cisco VPN and missing-MFA conditions Akira exploits for initial access. Lavawall® coexists with Defender, Huntress, Sophos, SentinelOne, and CrowdStrike, and surfaces their state alongside its own findings.

Start free →

Frequently asked

Is Akira still active?
Yes. Akira continues to be one of the most active ransomware groups affecting SMBs and healthcare practices.
What's the most important control to prevent Akira initial access?
MFA on VPN, RDP, and M365 access, combined with prompt patching of internet-facing remote-access appliances. Most Akira initial access comes from credentials and unpatched VPNs.
Should I pay the ransom if I'm hit?
Engage incident-response professionals immediately. Payment decisions involve legal, regulatory, and operational factors beyond the scope of a definition page. ThreeShield offers Tier 3 augmentation for MSPs handling active incidents.