Akira
Also known as Akira v2
Reports
121
First seen
May 22, 2024
Last seen
Aug 14, 2026
Motivation
Financial
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Victim regions
×1×33
United States×33
Germany×2
Guyana×2
Czechia×1
United Kingdom×1
Japan×1
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1486 Data Encrypted for Impact ×20T1566 Phishing ×13T1021 Remote Services ×9T1190 Exploit Public-Facing Application ×9T1021.001 Remote Services: Remote Desktop Protocol ×8T1133 External Remote Services ×8T1219 Remote Access Software ×8T1110 Brute Force ×7T1078 Valid Accounts ×7T1562.001 Impair Defenses: Disable or Modify Tools ×7T1562 Impair Defenses ×6T1195 Supply Chain Compromise ×6
Indicators
domain ×134filename ×127cve ×50ip_v4 ×39hash_sha256 ×12registry_key ×4hash_sha1 ×4hash_md5 ×3
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2024-40766 (exploited)CVE-2026-50751 (exploited)CVE-2024-47575 (exploited)CVE-2024-50383 (exploited)CVE-2025-37899CVE-2026-11645 (exploited)CVE-2026-1340 (exploited)CVE-2026-20131 (exploited)CVE-2026-20685CVE-2026-2441 (exploited)CVE-2026-33825 (exploited)CVE-2026-34908 (exploited)CVE-2026-34909 (exploited)CVE-2026-34910 (exploited)CVE-2026-34926 (exploited)CVE-2026-35273 (exploited)CVE-2026-35616 (exploited)CVE-2026-3909 (exploited)CVE-2026-3910 (exploited)CVE-2026-39987 (exploited)
Recent reports
High