Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Ransomware

Akira

Ransomware 2 detections found

Also known as: GOLD SAHARA, PUNK SPIDER, Howling Scorpius

Akira is a RaaS operation active since March 2023 that conducts double extortion using Windows, Linux, and VMware ESXi encryptors, frequently exploiting VPN/edge-device vulnerabilities for initial access. It has consistently ranked among the most active ransomware groups through 2025-2026, with cumulative extortion proceeds estimated above $250 million, and CISA/FBI updated their joint advisory as recently as November 2025 to reflect expanded targeting of critical infrastructure. As of late September 2026 there has been no major law-enforcement takedown of Akira's infrastructure.

Detection & eradication references

Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.

Detection rules

Source Rule Status Updated
sigma FTP Connection Open Attempt Via Winscp CLI experimental 2025-10-12
sigma Cloudflared Quick Tunnel Execution test 2023-12-20