Ransomware
Akira
Ransomware
2 detections found
Also known as: GOLD SAHARA, PUNK SPIDER, Howling Scorpius
Akira is a RaaS operation active since March 2023 that conducts double extortion using Windows, Linux, and VMware ESXi encryptors, frequently exploiting VPN/edge-device vulnerabilities for initial access. It has consistently ranked among the most active ransomware groups through 2025-2026, with cumulative extortion proceeds estimated above $250 million, and CISA/FBI updated their joint advisory as recently as November 2025 to reflect expanded targeting of critical infrastructure. As of late September 2026 there has been no major law-enforcement takedown of Akira's infrastructure.
Detection & eradication references
Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.
- #StopRansomware: Akira Ransomware — CISA/FBI/Europol/NCSC-NL
- Akira, GOLD SAHARA, PUNK SPIDER, Howling Scorpius, Group G1024 — MITRE ATT&CK
- Threat Assessment: Howling Scorpius (Akira Ransomware) — Palo Alto Networks Unit 42
Detection rules
| Source | Rule | Status | Updated |
|---|---|---|---|
| sigma | FTP Connection Open Attempt Via Winscp CLI | experimental | 2025-10-12 |
| sigma | Cloudflared Quick Tunnel Execution | test | 2023-12-20 |