Vexday analysis
Akira é uma entidade de implantação de ransomware ativa desde pelo menos março de 2023, rastreada pelo MITRE ATT&CK sob o identificador G1024 e também conhecida pelos nomes GOLD SAHARA, PUNK SPIDER e Howling Scorpius. O grupo utiliza credenciais comprometidas para acessar mecanismos de acesso externo com fator único de autenticação, como VPNs, e emprega ferramentas publicamente disponíveis para movimentação lateral nos ambientes comprometidos. Suas operações seguem o modelo de "dupla extorsão", no qual dados são exfiltrados antes da criptografia e a publicação dos arquivos é ameaçada caso o resgate não seja pago; variantes do ransomware são capazes de atingir sistemas Windows e hipervisores VMware ESXi. Com 17 técnicas documentadas no MITRE ATT&CK e 19 vítimas identificadas no Brasil, o grupo representa uma ameaça concreta ao ambiente corporativo brasileiro.
Attack chain
Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.
Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).
Techniques (MITRE ATT&CK) 17
How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.
Exploited vulnerabilities
No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.
Impact and victims
The group Akira has 19 known ransomware victims. See the most affected sectors and countries and recent victims.
Known infrastructure 110
Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).
c12dde993b1954bb7a890e0d6a3c1314Akirathreatfox9a7af0a766f7717d478c94414b15d25eAkirathreatfox904613f59987b5ebbc3e7d94b1390420Akirathreatfoxcb3ac44312acae80a626ba1aa593f4deAkirathreatfox9b3dce50e1056e6eca0faee733c33f35Akirathreatfoxf2bab102784860e65cd488387e42ca50Akirathreatfox251af0f2bea6c39064e162eac3b99ed6Akirathreatfox1c302704a76e2effc99f2d5e339d7f64Akirathreatfox266f33db148efc6ea7f978a246d36663Akirathreatfoxf1e9419110b9f316c070eca39bea63d6Akirathreatfox7d31b4d8fa391abaf49bf2c36d33fea2Akirathreatfox69446d7192ce7e5737bd9f7cbc7ca74aAkirathreatfoxbe6010d8bddef29ebbf3c8bb28f19517Akirathreatfox335d1205e666a401cc9ae6525a66546dAkirathreatfoxcf135dac1f6d5c72cb2f361aad02591fAkirathreatfoxa61ecd4bce5b291686756e7f1cda5c7bAkirathreatfoxba9e9d8577544204e544d91a4cfbed9bAkirathreatfox561a13e7c71a8ebd4db51d04e61ba1abAkirathreatfox6b96b2e3cbd523607816524e67c36539Akirathreatfoxe48e6c4a26379e2cf4a8e8c9a59ef094Akirathreatfox432fdcf8fc43c3871c3346bb2aeb3de2Akirathreatfox64622cb996b115fac71477650db0bb90Akirathreatfox0a52eca4d42889d0b3d21de101d4bea6Akirathreatfox1ff7de4a7b52e02a211e39831061916fAkirathreatfoxfe9b98bcd6fdab8766d8744e2ebda2c0Akirathreatfoxfe609cbd263e01a51c53ce0651ad0adeAkirathreatfox0bf7db6f6f756c1ce4346ac88727d04cAkirathreatfox493cf7c8d3ed22ce8990e6ef1c5bb1b5Akirathreatfox25f568d7838e70b4f8dafadd74a7d7fcAkirathreatfox78d5bbac805b333ec066c1a407403077Akirathreatfox+110 indicators in total. See them all on the IOCs page.
Akira uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.
Explore the AI Autonomous Pentest →