All threat actors

Threat actor profile

Akira aka Storm-1567, Howling Scorpius, Punk Spider, Gold Sahara

Global · financially motivatedVPN exploitation, fast encryption of Windows and hypervisorsUpdated

Akira is a ransomware operation that mainly hits small and medium-sized organisations in manufacturing, education, IT, healthcare and finance. According to CISA, affiliates typically enter through VPNs without MFA, stolen credentials or known flaws such as SonicWall CVE-2024-40766 and Veeam backup vulnerabilities. The group encrypts Windows systems and VMware ESXi hosts, and CISA first observed it encrypting Nutanix AHV virtual machines in June 2025. CISA says that as of late September 2025 Akira had claimed about $244.17 million in ransom proceeds.

LatestCISA updated advisory AA24-109A on 13 November 2025. ThreatDown reported on 8 September 2026 that its MDR team had handled multiple recent Akira intrusions through SonicWall devices still unpatched against CVE-2024-40766, two years after the fix was released.

Timeline

  1. Akira ransomware was first observed in March 2023, initially targeting Windows systems.

    CISA — AA24-109A #StopRansomware: Akira Ransomware (updated 13 Nov 2025)

  2. Affiliates began deploying a Linux variant against VMware ESXi virtual machines.

    CISA — AA24-109A #StopRansomware: Akira Ransomware (updated 13 Nov 2025)

  3. Akira began using Megazord, a Rust-based encryptor.

    CISA — AA24-109A #StopRansomware: Akira Ransomware (updated 13 Nov 2025)

  4. CISA and the FBI published the #StopRansomware advisory AA24-109A, citing about $42 million in proceeds as of January 2024.

    CISA — AA24-109A #StopRansomware: Akira Ransomware (updated 13 Nov 2025)

  5. Akira was first observed encrypting Nutanix AHV virtual machines.

    CISA — AA24-109A #StopRansomware: Akira Ransomware (updated 13 Nov 2025)

  6. CISA updated its advisory, citing about $244.17 million in ransom proceeds as of late September 2025.

    CISA — AA24-109A #StopRansomware: Akira Ransomware (updated 13 Nov 2025)

  7. ThreatDown reported recent Akira intrusions through SonicWall devices still unpatched against CVE-2024-40766.

    ThreatDown — This SonicWall bug is 2 years old. Akira ransomware is still exploiting it (8 Sep 2026)

Who is exposed, and what holds

Who is exposed

  • SonicWall SSL VPN and firewall customers who have not patched CVE-2024-40766 or reset credentials
  • Companies absorbing acquisitions with inherited VPNs, stale accounts and uneven EDR coverage
  • Operators of ESXi and Nutanix AHV virtualisation platforms

Recommended controls

  • Patch known exploited vulnerabilities on VPNs and backup servers first, then rotate VPN credentials
  • Enforce phishing-resistant MFA on all remote access
  • Keep encrypted, offline, immutable backups and segment hypervisor management

Sources