Akira
As of 2026-08-23, Akira is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 8 threats spanning ransomware, threat intel, vulnerability. Also known as Storm-1567, GOLD SAHARA, Howling Scorpius, Megazord. ATT&CK coverage spans 98 techniques across 15 tactics in 8 of 8 tracked threats. Most-observed techniques: T1078 (Valid Accounts), T1018 (Remote System Discovery), T1021.001 (Remote Desktop Protocol).
Also known as: Storm-1567, GOLD SAHARA, Howling Scorpius, Megazord, PUNK SPIDER
ATT&CK techniques observed
- T1078 Valid Accounts — Initial Access — observed in 6 of 8 tracked threats
- T1018 Remote System Discovery — Discovery — observed in 5 of 8 tracked threats
- T1021.001 Remote Desktop Protocol — Lateral Movement — observed in 5 of 8 tracked threats
- T1219 Remote Access Tools — Command And Control — observed in 5 of 8 tracked threats
- T1486 Data Encrypted for Impact — Impact — observed in 5 of 8 tracked threats
- T1490 Inhibit System Recovery — Impact — observed in 5 of 8 tracked threats
- T1087.002 Account Discovery: Domain Account — Discovery — observed in 4 of 8 tracked threats
- T1133 External Remote Services — Initial Access — observed in 4 of 8 tracked threats
- T1190 Exploit Public-Facing Application — Initial Access — observed in 4 of 8 tracked threats
- T1003 OS Credential Dumping — Credential Access — observed in 3 of 8 tracked threats
- T1021 Remote Services — Lateral Movement — observed in 3 of 8 tracked threats
- T1039 Data from Network Shared Drive — Collection — observed in 3 of 8 tracked threats
- T1059.001 PowerShell — Execution — observed in 3 of 8 tracked threats
- T1482 Domain Trust Discovery — Discovery — observed in 3 of 8 tracked threats
- T1555 Credentials from Password Stores — Credential Access — observed in 3 of 8 tracked threats
Tracked threats
- 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi) — HIGH
- Akira Ransomware Affiliate Forces Windows Safe Mode Reboot to Disable EDR, Exfiltrates Data via AnyDesk/WinRAR/s5cmd but Fails to Encrypt — HIGH
- Akira Ransomware Reboots Victims into Safe Mode to Blind EDR and Windows Defender — HIGH
- Identity Attacks Overtake Exploits as Top Ransomware Cause (Sophos State of Ransomware 2026) — INFO
- Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373) — CRITICAL
- Black Kite 2026 European Cyber Risk Report: Ransomware Surges 55.1% as Third-Party Supply Chains Become Europe's Primary Attack Path (Qilin-Led) — HIGH
- Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow Copy Deletion (SANS ISC Forensic Reconstruction, May 2026) — HIGH
- Veeam Backup & Replication 8 Critical Vulnerabilities — Domain User to Backup Server RCE (CVE-2026-21666, CVE-2026-21667, CVE-2026-21669, CVE-2026-21708) — CRITICAL
Related CVEs
CVE-2026-50752, CVE-2026-50751, CVE-2026-21708, CVE-2026-21672, CVE-2026-21671, CVE-2026-21670, CVE-2026-21669, CVE-2026-21668, CVE-2026-21667, CVE-2026-21666, CVE-2026-12569, CVE-2026-0257, CVE-2024-53704, CVE-2024-40766, CVE-2024-37085, CVE-2024-27198, CVE-2024-20481, CVE-2023-4966, CVE-2023-3519, CVE-2023-27532, CVE-2023-20269