{"id":8483,"date":"2025-11-15T10:03:47","date_gmt":"2025-11-15T10:03:47","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/15\/akira-ransomware-targets-over-250-organizations-extracts-42-million-in-ransom-payments-new-cisa-report\/"},"modified":"2025-11-15T10:03:47","modified_gmt":"2025-11-15T10:03:47","slug":"akira-ransomware-targets-over-250-organizations-extracts-42-million-in-ransom-payments-new-cisa-report","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/15\/akira-ransomware-targets-over-250-organizations-extracts-42-million-in-ransom-payments-new-cisa-report\/","title":{"rendered":"Akira Ransomware Targets Over 250 Organizations, Extracts $42 Million in Ransom Payments \u2013 New CISA Report"},"content":{"rendered":"<p>    Akira Ransomware Targets Over 250 Organizations, Extracts $42 Million in Ransom Payments \u2013 New CISA Report<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A new advisory from the Cybersecurity and Infrastructure Security Agency reveals that Akira ransomware has become one of the most active threats targeting businesses worldwide.<\/p>\n<p>Since March 2023, this ransomware group has impacted more than 250 organizations across North America, Europe, and Australia, amassing approximately $244.17 million in ransom proceeds as of late September 2025.<\/p>\n<p>The threat actors behind Akira have connections to the defunct Conti ransomware group. Akira ransomware primarily targets small and medium-sized businesses across multiple sectors.<\/p>\n<p>The group shows a strong preference for manufacturing, educational institutions, information technology, healthcare, and financial services sectors.<\/p>\n<p>The threat actors gain initial access through virtual private network services without multi-factor authentication configured, exploiting known vulnerabilities in Cisco products.<\/p>\n<p>CISA security analysts <a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/2025-11\/aa24-109a-stopransomware-akira-ransomware_3.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> that Akira threat actors have continuously evolved their attack methods throughout 2024 and 2025.<\/p>\n<p>The ransomware initially appeared as a Windows-specific C++ variant that encrypted files with the .akira extension.<\/p>\n<p>By April 2023, the group deployed a Linux variant targeting <a href=\"https:\/\/cybersecuritynews.com\/vmware-esxi-vcenter-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">VMware ESXi<\/a> virtual machines. In August 2023, they introduced the Megazord encryptor, a Rust-based tool that appends a .powerranges extension to encrypted files.<\/p>\n<p>In June 2025, Akira threat actors successfully encrypted Nutanix AHV virtual machine disk files by exploiting CVE-2024-40766, a SonicWall vulnerability.<\/p>\n<p>The ransomware employs a sophisticated hybrid encryption scheme that combines a ChaCha20 stream cipher with an RSA public-key cryptosystem for fast, secure key exchange.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-double-extortion-and-persistence-tactics\"><strong>Double Extortion and Persistence Tactics<\/strong><\/h2>\n<p>Akira operates using a double-extortion model that combines data encryption with threats to leak sensitive information.<\/p>\n<p>After gaining initial access, the threat actors establish persistence by creating new domain accounts and using credential-scraping tools such as Mimikatz and LaZagne to harvest passwords.<\/p>\n<p>They leverage legitimate remote access tools such as <a href=\"https:\/\/cybersecuritynews.com\/anydesk-users-login-credentials\/\" target=\"_blank\" rel=\"noreferrer noopener\">AnyDesk<\/a> and LogMeIn to maintain access while blending in with regular administrator activity.<\/p>\n<p>For data exfiltration, the group uses tools such as <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploited-github\/\" target=\"_blank\" rel=\"noreferrer noopener\">FileZilla<\/a>, WinSCP, and RClone to transfer stolen data to cloud storage services before encrypting it.<\/p>\n<p>To inhibit system recovery, the <a href=\"https:\/\/cybersecuritynews.com\/large-scale-akira-ransomware\/\" target=\"_blank\" rel=\"noreferrer noopener\">Akira<\/a> encryptor uses PowerShell commands to delete Volume Shadow Copy Service copies on Windows systems.<\/p>\n<p>The ransom note appears as fn.txt or akira_readme.txt and provides victims with instructions to contact the threat actors through a .onion URL accessible via the Tor network, with payments demanded in Bitcoin.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/akira-ransomware-targets-over-250-organizations\/\">Akira Ransomware Targets Over 250 Organizations, Extracts $42 Million in Ransom Payments \u2013 New CISA Report<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/akira-ransomware-targets-over-250-organizations\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Akira Ransomware Targets Over 250 Organizations, Extracts $42 Million in Ransom Payments \u2013 New CISA Report A new advisory from the Cybersecurity and Infrastructure Security Agency reveals that Akira ransomware has become one of the most active threats targeting businesses worldwide. Since March 2023, this ransomware group has impacted more than 250 organizations across North [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-8483","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8483"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8483"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8483\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8483"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8483"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8483"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}