Home · Wiki · Entities & Threat Actors
created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [ransomware-group, supply-chain] · confidence: medium · affected_sectors: [] · au_impact: false

Akira

Akira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement.

Attribute Detail
ATT&CK ID G1024
Aliases GOLD SAHARA, PUNK SPIDER, Howling Scorpius
Attribution Not stated by MITRE ATT&CK
Class ecrime
Active since
ATT&CK entry created 2024-02-20
Techniques mapped 25

Attribution — as claimed

Not state-attributed; the activity is self-declared (public extortion/leak-site claims) or attributed to criminal reporting.

Known TTPs

Technique Name
T1018 Remote System Discovery
T1021.001 Remote Desktop Protocol
T1027.001 Binary Padding
T1036.005 Match Legitimate Resource Name or Location
T1059.001 PowerShell
T1078 Valid Accounts
T1133 External Remote Services
T1213.002 Sharepoint
T1219 Remote Access Tools
T1482 Domain Trust Discovery
T1486 Data Encrypted for Impact
T1531 Account Access Removal

(First 12 of 25 ATT&CK-mapped techniques.)

Related Pages

  • Mitre Attack — the framework this page's data is drawn from
  • Silence — similarly attributed-linked actor, same attribution class
  • Lapsus — similarly attributed-linked actor, same attribution class
  • Scattered Spider — similarly attributed-linked actor, same attribution class

Provenance

Stub generated from MITRE ATT&CK G1024 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.