Avatier

Threat actor

Akira

FBI, CISA and international partners say Akira ransomware actors have hit a wide range of businesses and critical infrastructure entities in North America, Europe and Australia since March 2023.Source [1]

What authorities and investigators report

  • The November 2025 update says Akira actors primarily target small and medium-sized businesses, with a notable preference for educational institutions and organizations in sectors such as critical manufacturing and information technology.Source [1]
  • The FBI and researchers observed Akira actors gaining initial access through VPN services that did not have multifactor authentication configured, mostly by exploiting known vulnerabilities.Source [1]
  • The advisory says Akira actors also used spearphishing and valid credentials for initial access, and used password spraying tools such as SharpDomainSpray to gain account credentials.Source [1]
  • According to the authoring organizations and open source reporting, Akira actors attempted to establish persistence by creating new domain accounts, used post-exploitation techniques such as Kerberoasting, and used credential scraping tools like Mimikatz to aid privilege escalation.Source [1]
  • The advisory says that, after exfiltrating data, Akira actors used a double-extortion model: encrypting systems and threatening to leak sensitive information.Source [1]

Techniques

Attack vectors

Sources

  1. #StopRansomware: Akira Ransomware (AA24-109A) — CISA, 2025-11-13

Last reviewed Oct 2, 2026