White Paper
THREAT PROFILE: Akira Ransomware
Akira is a ransomware-as-a-service (RaaS) group first identified in 2023 that uses a double-extortion strategy, encrypting systems while stealing sensitive data and threatening to publish it if ransom demands are not met. The group has primarily targeted organizations in manufacturing, construction and engineering, and consumer-related industries, exploiting the critical nature of their operations to increase pressure on victims. This threat profile examines Akira’s targeted industries and regions, known exploited vulnerabilities, affiliations, attack tools, and behaviors across both Windows and Linux environments. It also maps the group’s tactics, techniques, and procedures to the MITRE ATT&CK framework, providing insight into how attacks progress from initial access and reconnaissance to
