LIVE
LATEST THREAT: Akira Ransomware 2026: ESXi Targeting, $245M in Payments, and the Linux Encryptor THREAT ALERT ACTIVE
Intelligence DB / Group Profile Akira

Akira Ransomware 2026: ESXi Targeting, $245M in Payments, and the Linux Encryptor

Akira is one of the most active ransomware groups in 2026, claiming 84 victims in March alone and over 1,400 since emerging in 2023. This profile covers Akira's current TTPs, the ESXi and Linux encryptors, the Nutanix AHV targeting development, and what defenders need to know.

By Ransomware Tracker ·
AkiraransomwareESXiLinuxVMwareNutanixAHVdouble extortiondata leakRaaS2026group-profileCISA
Threat Level
8/10
Sectors Targeted
manufacturing
professional-services
financial-services
technology
construction
legal
Ransomware Family
Akira

Overview

Akira emerged in March 2023 as a double-extortion ransomware group targeting Windows environments. By April 2023, the group had deployed a Linux variant specifically engineered for VMware ESXi hypervisors. By mid-2026, Akira has claimed over 1,400 victims, extracted at least $245 million in ransom payments, and is consistently ranked among the top two or three most active ransomware operations globally.

What distinguishes Akira from many contemporaries is the deliberate expansion beyond standard Windows endpoint encryption. The group’s investment in ESXi, Linux, and most recently Nutanix AHV encryptors reflects a strategic decision to target the virtualisation layer where enterprises consolidate their most critical workloads — a single encryptor execution on a hypervisor can effectively take down hundreds of virtual machines simultaneously.

Victimology and Activity Levels

Akira’s most active period on record was March 2026, when the group posted 84 victims to their dark web leak site. The group had previously set a monthly record with 72 victims in November 2025. Geographically, the United States absorbs approximately 50% of attacks, with the UK, Canada, Germany, and Australia making up the bulk of the remainder.

Sector distribution has shifted over time. Manufacturing, professional and legal services, and construction and engineering now account for a disproportionate share of victims — sectors that are characteristically under-invested in security controls relative to their operational criticality and their ability to pay.

Technical Profile

Initial Access

Akira’s primary initial access methods:

  • VPN credential abuse: Exploitation of Cisco ASA and Cisco AnyConnect VPN appliances, including the 2023 zero-day CVE-2023-20269. Stolen credentials from infostealer logs or brute-forcing against accounts without MFA are the most common vector.
  • External-facing remote services: RDP and Citrix Gateway remain frequent targets when not protected by MFA.
  • Spearphishing: Less common than the VPN route but documented in incidents involving specific, named executives.

Lateral Movement and Persistence

Post-access, Akira operators follow a relatively standardised playbook:

  • Credential harvesting: Mimikatz, secretsdump.py (Impacket), and LSASS memory dumping via comsvcs.dll for credential extraction.
  • Discovery: Advanced IP Scanner, SoftPerfect Network Scanner, PCHunter, and SharpHound for Active Directory enumeration.
  • Lateral movement: PsExec, WMI execution, and RDP with harvested credentials.
  • C2 tunnelling: Ngrok, Cloudflare Tunnel, and MobaXterm have been documented as C2 relay mechanisms to bypass perimeter monitoring.
  • Persistence: New domain accounts, backdoor implants, and modifications to existing scheduled tasks.

Exfiltration

Before encryption, Akira exfiltrates data to support the double-extortion model. Common exfiltration tools include RClone to cloud storage (MEGA, pCloud), WinSCP, and custom PowerShell scripts. The exfiltration phase typically precedes the encryption deployment by days to weeks, and the data staging phase is often the most detectable moment in the attack chain.

Windows Encryption

Akira’s Windows encryptor targets file extensions selectively, skipping Windows system directories and executable file types. It uses NTRUEncrypt combined with ChaCha20 for file encryption — a symmetric key per file, encrypted with the asymmetric key pair. Encrypted files receive the .akira extension. VSS copies and Windows Recovery Environment components are deleted.

Linux and ESXi Encryption

The Linux variant was released in April 2023 and targets ESXi environments specifically. Written in C++, it enumerates running VMs using ESXi’s command-line tools (esxcli, vim-cmd) and terminates them before beginning encryption. This avoids file locking issues that would prevent encryption of VM disk files (.vmdk, .vmx).

Encrypted ESXi files receive the .akira extension. The encryptor does not delete backups on the ESXi host itself but typically operates after operators have already accessed and encrypted or deleted network-accessible backup repositories.

In June 2025, Akira was observed deploying a variant targeting Nutanix Acropolis Hypervisor (AHV) environments — the first documented Akira attack against the Nutanix platform. The AHV targeting represents Akira’s continued investment in hypervisor-specific encryptors across multiple virtualisation platforms, not just VMware.

The CISA Advisory and Affiliate Network

CISA issued a joint advisory (AA24-109A) with the FBI, Europol, and NCSC in April 2024 identifying Akira’s tactics in detail. The advisory confirmed Akira operates as a Ransomware-as-a-Service model, with core developers maintaining the infrastructure and affiliate operators conducting intrusions.

The affiliate recruitment process is selective relative to some competitors. Akira’s operators have been observed recruiting for experience with enterprise environments specifically, which helps explain the relatively consistent technical quality of the attack chains compared to lower-tier RaaS operations that accept any willing affiliate.

The Rust Rewrite

Akira briefly deployed a Rust-based version of the Windows encryptor in late 2023 (referred to as “Megazord” in some reporting). The Rust variant was withdrawn relatively quickly and the group returned to the C++ codebase. The Rust experiment is notable as an example of the trend toward Rust-based ransomware — it complicates static analysis and reduces detection rates from some AV products — but Akira’s primary deployments remain C++ based.

Data Leak Site

Akira maintains a dark web leak site hosted on Tor. Victims are posted with a countdown to publication of exfiltrated data if payment is not received. The site has a distinctive aesthetic — an 80s retro design with a terminal-style interface — and is functional and updated regularly.

A second site specifically for data downloads (separate from the main extortion site) has been used in some campaigns. Published victim data is typically available for several months before being removed or replaced.

Defensive Priorities

Given Akira’s consistent use of VPN credential compromise as the initial access vector:

  • MFA on all VPN, RDP, and remote access is the single highest-impact control.
  • Patch Cisco ASA and AnyConnect promptly — Akira specifically targeted known Cisco vulnerabilities.
  • Monitor for credential-dumping tools: Detection rules for Mimikatz execution, LSASS access via comsvcs.dll, and Impacket tool signatures catch Akira operators during the post-access phase.
  • Alert on RClone and cloud storage uploads: RClone to MEGA or pCloud from endpoints or servers is an anomalous pattern worth investigating regardless of context.
  • ESXi hardening: Restrict SSH access to ESXi management interfaces, ensure ESXi hosts are not reachable from user network segments, and monitor for unexpected VM power-off events that precede encryption.
  • Nutanix AHV: Organisations running Nutanix AHV should review access controls to the Prism management plane and ensure it is not accessible from potentially compromised user segments.

A CISA-aligned recovery posture — isolated backups not accessible from the production network, tested restoration procedures, and network segmentation that prevents a compromised workstation from reaching domain controllers or backup infrastructure — is the best protection against Akira’s multi-stage attack chain achieving its maximum impact.

// Related Intelligence
Group Profile

Arcus Media: The RaaS Operation Targeting Healthcare and Critical Infrastructure

Group Profile

Embargo Ransomware: Rust-Based RaaS Targeting Enterprise and Healthcare

Group Profile

Spirals Ransomware: New Group Completes Full Attack Chain in Under 24 Hours