created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [ransomware-group, supply-chain] · confidence: medium · affected_sectors: [] · au_impact: false
Akira
Akira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement.
| Attribute | Detail |
|---|---|
| ATT&CK ID | G1024 |
| Aliases | GOLD SAHARA, PUNK SPIDER, Howling Scorpius |
| Attribution | Not stated by MITRE ATT&CK |
| Class | ecrime |
| Active since | — |
| ATT&CK entry created | 2024-02-20 |
| Techniques mapped | 25 |
Attribution — as claimed
Not state-attributed; the activity is self-declared (public extortion/leak-site claims) or attributed to criminal reporting.
Known TTPs
| Technique | Name |
|---|---|
T1018 |
Remote System Discovery |
T1021.001 |
Remote Desktop Protocol |
T1027.001 |
Binary Padding |
T1036.005 |
Match Legitimate Resource Name or Location |
T1059.001 |
PowerShell |
T1078 |
Valid Accounts |
T1133 |
External Remote Services |
T1213.002 |
Sharepoint |
T1219 |
Remote Access Tools |
T1482 |
Domain Trust Discovery |
T1486 |
Data Encrypted for Impact |
T1531 |
Account Access Removal |
(First 12 of 25 ATT&CK-mapped techniques.)
Related Pages
- Mitre Attack — the framework this page's data is drawn from
- Silence — similarly attributed-linked actor, same attribution class
- Lapsus — similarly attributed-linked actor, same attribution class
- Scattered Spider — similarly attributed-linked actor, same attribution class
Provenance
Stub generated from MITRE ATT&CK G1024 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.