BushidoUK RVM Profile: Akira

Fecha
18 Jun 2026
Actor
akira
Tipo
Threat-actor
Pais
United Kingdom
Sector
-
Confianza
high
90
Prioridad analitica
Alta

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

8IOCs
0TTPs
akiraActor
United KingdomPais
Executive Summary
Perfil del grupo ransomware segun BushidoUK Ransomware Vulnerability Matrix. Incluye vulnerabilidades conocidas, herramientas y TTPs asociadas.

Key Points

  • Source: BushidoUK RVM GroupProfiles
  • BushidoUK RVM Repository

Group Profile: Akira

Perfil del grupo ransomware segun BushidoUK Ransomware Vulnerability Matrix. Incluye vulnerabilidades conocidas, herramientas y TTPs asociadas.

Akira's Exploited Vulnerabilities

> [!NOTE]

> This is the list of vulnerabilities that have been observed during intrusions that lead to Akira ransomware deployment or data exfiltration and leaks published to Akira's Tor Site

Cisco

| Product | CVE(s) | Ransomware Group(s) | Source(s) |

|---|---|---|---|

| ASA & FTD | CVE-2023-20269 | Akira | cisco.com |

| ASA & FTD | CVE-2023-20263 | Akira | blog.talosintelligence.com|

| ASA & FTD | CVE-2020-3259 | Akira | cisa.gov |

Fortinet

| Product | CVE(s) | Ransomware Group(s) | Source(s) |

|---|---|---|---|

| FortiOS | CVE-2022-40684 | Akira | stairwell.com |

| FortiOS | CVE-2019-6693 | Akira | stairwell.com |

| FortiClient | CVE-2023-48788 | Akira | blog.talosintelligence.com|

SonicWall

| Product | CVE(s) | Ransomware Group(s) | Source(s) |

|---|---|---|---|

| SonicOS SSL-VPN | CVE-2024-40766 | Akira | arcticwolf.com |

Veeam

| Product | CVE(s) | Ransomware Group(s) | Source(s) |

|---|---|---|---|

| Backup & Replication | CVE-2024-40711 | Akira | @SophosXOps |

| Backup & Replication | CVE-2023-27532 | Akira | sophos.com |

VMware

| Product | CVE(s) | Ransomware Group(s) | Source(s) |

|---|---|---|---|

| ESXi | CVE-2024-37085 ("ESX Admins") | Akira | microsoft.com |

| vSphere Client | CVE-2021-21972 | Akira | qualys.com |

---

#### Sources

| Date Published | Report |

|---|---|

| 10 Oct 2024 | https://infosec.exchange/@SophosXOps/113284564225476186 |

| 2 Oct 2024 | https://blog.qualys.com/vulnerabilities-threat-research/2024/10/02/threat-brief-understanding-akira-ransomware |

| 6 Sept 2024 | https://arcticwolf.com/resources/blog/arctic-wolf-observes-akira-ransomware-campaign-targeting-sonicwall-sslvpn-accounts/ |

| 29 July 2024 | https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/

| 18 April 2024 | https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-109a |

| 21 Dec 2023 | https://news.sophos.com/en-us/2023/12/21/akira-again-the-ransomware-that-keeps-on-taking/ |

| 6 Sept 2023 | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC#fs |

| 23 Aug 2023 | https://stairwell.com/resources/akira-pulling-on-the-chains-of-ransomware/ |

Referencias

Diamond Model

Adversary
akira
Ver perfil →
Victim
BushidoUK RVM Profile: Akira
United Kingdom
Capability
Threat-actor
Infrastructure
infosec.exchange
blog.qualys.com
arcticwolf.com
www.microsoft.com

Relations

Mapa de nodos relacionados por IOCs compartidos, actor, enlaces IntelTracker/OSINT, campanas y victimas observadas. Haz click en un nodo para abrir el post, filtro o fuente.

16 enlaces

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
Domain infosec.exchange Extraido del contenido VT OffSec SOCRadar
Domain blog.qualys.com Extraido del contenido VT OffSec SOCRadar
Domain arcticwolf.com Extraido del contenido VT OffSec SOCRadar
Domain www.microsoft.com Extraido del contenido VT OffSec SOCRadar
Domain www.cisa.gov Extraido del contenido VT OffSec SOCRadar
Domain news.sophos.com Extraido del contenido VT OffSec SOCRadar
Domain sec.cloudapps.cisco.com Extraido del contenido VT OffSec SOCRadar
Domain stairwell.com Extraido del contenido VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor akira en el blog → Ver akira en IntelTracker → Fuente OSINT: github.com→ Fuente OSINT: raw.githubusercontent.com → Buscar akira en APTTrail → Repositorio APTTrail → Mas incidentes en United Kingdom → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes