Overview

Akira ransomware is a strain of ransomware that emerged in March 2023 and has since targeted various industry sectors, including education, finance, real estate, manufacturing, and consulting.

The ransomware deletes shadow volume copies on victim devices via a PowerShell command prior to encrypting victim files and adding the ‘.akira’ file extension. Akira uses the Windows Restart Manager application programming interface (API) to terminate processes or shut down Windows services that keep files open so as not to interfere with encryption. Prior to encryption, Akira steals corporate data from its victims to use as leverage in negotiations for unlocking encrypted files later. The malware gains initial access to systems through various means, including search engine optimisation (SEO) poisoning or malvertising.

Akira’s ransom notes contain ‘akira_readme.txt’ files that contain links to Akira’s ransomware extortion blog and instructions on how victims can negotiate the release of their files.

The ransomware exploited at least 16 victims within the first two months of its existence. Akira ransomware operators use a unique negotiation system and host a TOR-based (.onion) website where victims are listed along with any stolen data, should a victim fail to comply with the ransom demands.

Download this report

Further Malware Reports from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

Colorado, USA Office

950 S Cherry St Ste 505
Denver, Colorado
USA
80246

Dubai, UAE Office

Meydan Grandstand
6th floor
Meydan Road
Nad AI Sheba
Dubai, U.A.E

Colorado, USA Office

950 S Cherry St Ste 505
Denver, Colorado
USA
80246

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Arizona, USA Office

1300 S Litchfield Rd
110-L, Goodyear
USA
Arizona 85338

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

950 S Cherry St Ste 505
Denver, Colorado
USA
80246

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



COLORADO, USA OFFICE
950 S Cherry St Ste 505
Denver, Colorado
USA
80246


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content