Threat Intelligence / Actor / Akira

Akira

As of 2026-08-23, Akira is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 8 threats spanning ransomware, threat intel, vulnerability. Also known as Storm-1567, GOLD SAHARA, Howling Scorpius, Megazord. ATT&CK coverage spans 98 techniques across 15 tactics in 8 of 8 tracked threats. Most-observed techniques: T1078 (Valid Accounts), T1018 (Remote System Discovery), T1021.001 (Remote Desktop Protocol).

Nation: Russia · 8 tracked threat(s) · Categories: RANSOMWARE, THREAT_INTEL, VULNERABILITY

Also known as: Storm-1567, GOLD SAHARA, Howling Scorpius, Megazord, PUNK SPIDER

ATT&CK techniques observed

98 techniques observed across 8 of 8 tracked threats · Credential Access (13), Discovery (12), Initial Access (10), Defense Evasion (9), Execution (9), Lateral Movement (7)

Tracked threats

Related CVEs

21 CVEs referenced by tracked Akira activity

CVE-2026-50752, CVE-2026-50751, CVE-2026-21708, CVE-2026-21672, CVE-2026-21671, CVE-2026-21670, CVE-2026-21669, CVE-2026-21668, CVE-2026-21667, CVE-2026-21666, CVE-2026-12569, CVE-2026-0257, CVE-2024-53704, CVE-2024-40766, CVE-2024-37085, CVE-2024-27198, CVE-2024-20481, CVE-2023-4966, CVE-2023-3519, CVE-2023-27532, CVE-2023-20269

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence