Akira Ransomware in 2026: The RaaS Crew That Owns 40% of the Market
TL;DR
Akira ransomware, first seen in March 2023, is not just another RaaS crew. Insurance provider At-Bay's 2026 InsurSec Report — drawn from 6,500+ claims — confirms Akira accounts for more than 40% of all ransomware claims in their dataset. That is an extraordinary market share for a single threat actor. Average demands have hit $1.2M, roughly 50% above peers. Their signature move: exploit SonicWall VPN (CVE-2024-40766), exfiltrate sensitive data in under two hours, and then encrypt. Sixty percent of victims had EDR deployed. It didn't matter. This profile unpacks why, and what actually stops them.
Background: From Conti's Ashes
Akira emerged in late Q1 2023, roughly coinciding with the operational collapse of Conti — one of the most prolific ransomware enterprises in history. Researchers at multiple firms have noted overlapping code patterns, personnel movement indicators, and affiliate network crossover between Conti's remnants and Akira's early operations. The group is assessed as Russian-speaking, technically sophisticated, and entirely profit-motivated with no known state nexus.
What separated Akira from the dozens of post-Conti splinters: operational discipline. While groups like Royal and BlackSuit fragmented into inconsistent affiliates, Akira built a structured RaaS with clear TTP consistency across intrusions, a distinctive retro-80s green-screen Tor leak site, and a victim communication model that scales — ransom negotiations only through Tor portals, no initial demand left at the scene.
By late 2025, Akira had collected over $244 million in ransom payments with approximately five-times year-over-year revenue growth. In April 2026, they are still accelerating. Victims in the past 30 days alone include Alkegen (specialty materials, USA), Kubiak Melton & Associates (financial services, USA), and a Los Angeles law firm with 10GB of legal documents exfiltrated.
Technical Analysis
Phase 1: Initial Access — The VPN Problem
Akira's primary entry vector in 2025–2026 is unambiguous: VPN credential compromise. At-Bay's claims data shows 73% of ransomware incidents in 2025 began with VPN compromise — nearly double the rate from two years prior. Akira is the single largest driver of that statistic.
SonicWall devices appear in 86% of Akira-linked attacks, per At-Bay's analysis. The primary weapon: CVE-2024-40766, a critical improper access control vulnerability in SonicWall SonicOS SSL-VPN and management interfaces. CVSS 9.3. CISA added it to KEV in September 2024; many organizations still have not patched.
Beyond SonicWall, Akira operators have exploited:
- CVE-2023-20269 — Cisco ASA/FTD unauthorized remote access vulnerability, enabling brute-force and credential stuffing against VPN session establishment
- Veeam Backup & Replication flaws (CVE-2024-40711 and predecessors) — targeting backup infrastructure for credential theft and shadow copy destruction
- Credentials sourced from initial access brokers (IABs) operating on Russian cybercrime forums — Akira affiliates routinely purchase pre-authenticated footholds to skip the exploitation phase entirely
Phase 2: Discovery and Credential Harvesting (Dwell: <2 Hours)
Once inside, Akira actors move with exceptional velocity. CISA's November 2025 advisory confirmed documented intrusions where complete data exfiltration occurred in just over two hours from initial access. This is not a bug — it is a feature of their operational model.
Discovery toolkit:
- ADFind — Active Directory enumeration, pulling group memberships, OUs, and domain controller topology
- Nmap / NetScan — network topology mapping for VM host identification and lateral movement planning
- SharpHound (BloodHound ingestor) — BloodHound-compatible graph data collection for attack path identification to domain admin
Credential harvesting:
- Kerberoasting — requesting Kerberos service tickets for service accounts, then offline-cracking weak passwords
- LSA dump / Mimikatz variants — extracting NTLM hashes and plaintext credentials from LSASS memory
- Targeted domain controller compromise — Akira consistently prioritizes DC access as the pivot for ransomware deployment authority
Persistence mechanisms:
- Deployment of legitimate remote access tools: AnyDesk, LogMeIn, RustDesk — these blend into normal enterprise traffic and survive initial incident response sweeps
- Creation of new domain accounts with administrative privileges as backup access channels
Phase 3: Exfiltration
Akira runs exfiltration before encryption — always. The double-extortion model requires stolen data to be usable as a threat independent of decryption. Their exfiltration stack:
- WinRAR — compression and archiving of targeted data (financial records, legal documents, PII, M&A data, patient records)
- FileZilla / WinSCP / RClone — data transfer to attacker-controlled cloud storage (RClone is increasingly preferred for its support of 40+ cloud backends and native encryption)
- Ngrok — encrypted tunnel creation to bypass egress monitoring and firewall outbound rules
- MegaSync / cloud storage abuse — exfiltration disguised as legitimate cloud sync traffic
Volume targets: typically 10–100GB of strategically selected data. Akira actors demonstrate file system awareness — they are not bulk-copying everything. Legal documents, financial records, personal data, and credentials are prioritized.
Phase 4: Encryption — Hybrid ChaCha20/RSA
Akira's encryption implementation is technically sophisticated:
- ChaCha20 for symmetric file encryption (performance-optimized, no OpenSSL dependency)
- RSA-4096 for encrypting the per-file ChaCha20 keys (making decryption impossible without the actor's private key)
- File extensions appended:
.akira,.akiranew,.powerranges,.aki(variant-dependent) - No ransom note on disk — victims find only encrypted files and must initiate contact through the Tor portal
The Linux/ESXi variant (first observed mid-2023) targets VMware ESXi hypervisors — a single encryption operation can lock an entire virtual machine fleet. In June 2025, a new encryptor targeting Nutanix AHV environments emerged, expanding Akira's virtualization attack surface to one of VMware's primary alternatives.
The ESXi/AHV targeting is strategically rational: a single ESXi host may run dozens of production VMs. Encrypting the VMDK/VHDX files at the hypervisor level bypasses guest-level defenses entirely.
Why EDR Isn't Stopping Them
The At-Bay statistic deserves emphasis: 60% of Akira victims had EDR deployed. This is not an indictment of EDR as a category — it is a map of exactly how Akira bypasses it.
Vector 1: Pre-EDR initial access. VPN exploitation occurs before EDR ever sees a process. The attacker is authenticated as a valid network user before any endpoint telemetry triggers.
Vector 2: Living-off-the-land binaries. ADFind, built-in Windows tools (net.exe, nltest.exe, wmic.exe), and legitimate RMM tools (AnyDesk, LogMeIn) do not generate malware signatures. Behavioral rules exist but require tuning.
Vector 3: Speed beats investigation. Sub-2-hour exfiltration means that even when an alert fires, the data is already gone before an analyst reviews the queue. EDR generates the alert; nobody acts on it in time.
Vector 4: Hypervisor-level encryption. ESXi/Nutanix encryptors operate at the hypervisor layer, below the OS where EDR agents run. No agent on the VM can observe or block the VMDK encryption happening on the host.
At-Bay's finding that MDR + 24/7 monitoring reduced full encryption events is the correct takeaway: the control that matters is detection speed → response speed, not detection alone.
2026 Campaign Activity
April 2026 Akira victims (confirmed or claimed on leak site):
- Alkegen (alkegen.com) — advanced materials manufacturer, USA — claimed April 23, 2026
- Kubiak Melton & Associates — financial services, USA — claimed April 22, 2026
- Multiple additional victims across manufacturing, healthcare, and legal sectors in Q1 2026
The group's cadence has not slowed. CISA and FBI continue to list Akira in top-5 active ransomware advisories. Law enforcement actions (DOJ indictments, international arrests) have not materially disrupted affiliate operations.
IOCs / Indicators of Compromise
File System:
Extensions: .akira | .akiranew | .powerranges | .aki
Ransom note: NONE (no on-disk note; victim directed to Tor portal)
Staging directories: C:\ProgramData\, C:\Windows\Temp\ (common)
Network / Infrastructure:
Exfiltration: RClone (rclone.exe), FileZilla, WinSCP, Ngrok tunnels
C2/Comms: Tor-based victim portal (rotates; no static hostname)
Remote access: AnyDesk (GUI), LogMeIn (GUI), RustDesk
Process / Behavioral:
adfind.exe -f "(objectcategory=person)" (AD user enumeration)
nltest.exe /domain_trusts (trust relationship mapping)
net.exe group "domain admins" /domain
vssadmin delete shadows /all /quiet (shadow copy destruction pre-encryption)
wbadmin delete catalog -quiet (backup catalog deletion)
bcdedit /set {default} bootstatuspolicy ignoreallfailures (disabling recovery)
CVEs Actively Exploited:
CVE-2024-40766 — SonicWall SonicOS SSL-VPN, CVSS 9.3 (CISA KEV)
CVE-2023-20269 — Cisco ASA/FTD unauthorized VPN access
CVE-2024-40711 — Veeam Backup & Replication RCE
MITRE ATT&CK TTPs:
T1133 — External Remote Services (VPN exploitation)
T1078 — Valid Accounts (credential purchase/theft)
T1059 — Command and Scripting Interpreter
T1486 — Data Encrypted for Impact
T1041 — Exfiltration Over C2 Channel
T1490 — Inhibit System Recovery
T1087 — Account Discovery (ADFind)
T1558.003 — Steal or Forge Kerberos Tickets: Kerberoasting
Lyrie Take
Akira's dominance reveals a structural problem in enterprise defense that transcends any individual vulnerability. When one ransomware affiliate program can claim 40% of insured ransomware losses, it means the defenses being deployed are systematically miscalibrated against the actual attack chain.
The SonicWall statistic is damning. CVE-2024-40766 has been in CISA KEV since September 2024 — nineteen months ago at time of writing. Akira is exploiting it in 86% of their attacks. This is not a zero-day problem. This is a patching velocity problem, a perimeter visibility problem, and an asset inventory problem all compounding each other.
The EDR failure story is equally instructive. Organizations are buying endpoint detection and calling it ransomware defense. Akira treats the endpoint layer as irrelevant — they live in network infrastructure, move through legitimate tools, and encrypt at the hypervisor where no endpoint agent can see them.
What Lyrie's autonomous defense model addresses here: The critical gap is detection latency. Akira's 2-hour exfiltration window is designed to beat human analyst response time. It does not beat machine-speed behavioral correlation. An AI-native defense layer that simultaneously monitors VPN authentication anomalies, lateral movement indicators (ADFind spawn, Kerberoasting service ticket volume spikes), and unexpected RClone/Ngrok egress — and correlates them into an attack chain signal within seconds — closes the window that Akira exploits.
Human analysts reviewing EDR queues at shift handover do not stop Akira. Autonomous systems correlating signals at machine speed do.
Defender Playbook
Immediate (this week):
1. Patch SonicWall — CVE-2024-40766 has no excuse to be unpatched in your environment. Run show version on every SonicOS appliance. Target: 7.1.1-7058 or later.
2. Audit VPN MFA — Ensure every VPN account requires phishing-resistant MFA (hardware keys or TOTP minimum). SMS is insufficient.
3. Enumerate AnyDesk/LogMeIn/RustDesk instances — Any unauthorized installations are post-compromise persistence. Hunt now.
4. Shadow copy audit — Verify VSS is protected. Test that vssadmin list shadows returns expected snapshots.
Short-term (30 days):
5. Deploy network-level behavioral detection — Specifically: ADFind execution, nltest.exe domain queries, Kerberoasting service ticket spikes (>10 TGS requests from single account in 60 seconds), and unexpected RClone/Ngrok egress on any host.
6. ESXi/Nutanix hardening — Disable SSH on ESXi hosts when not in use; implement host-based firewall rules limiting management access to jump hosts only. For Nutanix: audit Prism Central access roles.
7. Backup immutability verification — Air-gapped or immutable backups that Akira cannot reach via domain credentials. Test restoration quarterly.
Strategic:
8. MDR over EDR-alone — At-Bay's data is clear: EDR + 24/7 MDR prevented full encryption events; EDR alone did not. If you cannot staff 24/7 detection internally, acquire it externally.
9. Incident response pre-authorization — Have your IR firm's retainer signed, your IR runbook tested, and your legal/PR notification tree documented before an incident. Akira's 2-hour window does not accommodate vendor procurement.
10. Ransom payment pre-authorization clarity — Know your board's position on payment before you need it. The $1.2M average demand and the 62% negotiated-down reality mean preparation matters.
Sources
1. ConnectWise — "Akira Ransomware: A Complete Threat Profile" (April 24, 2026): https://www.connectwise.com/blog/akira-ransomware
2. At-Bay — 2026 InsurSec Report (analyzed 6,500+ claims, 100,000+ policy years): https://www.reinsurancene.ws/ransomware-is-shifting-towards-infrastructure-led-exploitation-at-bay-reports/
3. CISA Advisory AA24-109A — "#StopRansomware: Akira Ransomware": https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-109a
4. DeXpose — Akira claims on Alkegen (April 23, 2026): https://www.dexpose.io/akira-strikes-alkegen-ransomware-attack-on-specialty-materials-leader/
5. DeXpose — Akira claims on Kubiak Melton & Associates (April 22, 2026): https://www.dexpose.io/akira-ransomware-strikes-kubiak-melton-associates/
6. MITRE ATT&CK — Akira group profile and TTP mapping: https://attack.mitre.org/
Lyrie.ai Cyber Research Division — Senior Analyst Desk
Lyrie Verdict
Lyrie's autonomous defense layer flags this class of exposure the moment it surfaces — no signature update required.