OAK — OnChain Attack Knowledge

Software · OAK-S33 · ransomware

OAK-S33 — Akira ransomware

Type
ransomware
Aliases
Akira (the operator-side and leak-site-branded name from the brand's March 2023 debut, with the leak-site visual identity adopting a deliberate retro-1980s green-on-black terminal aesthetic that became the family's most-recognisable surface signature); Megazord (a short-lived Rust-language Linux/ESXi variant identifier used in mid-2023 builds before consolidation back under the Akira brand); industry-side cross-attribution labels include the informal "Akira-Conti-derivative" naming used in 2023 industry reporting that documented partial code-reuse signals between the Akira Windows codebase and the Conti v3 leaked source. Akira is widely read by Mandiant, Sophos, and Avast as a Conti-cohort-adjacent operator emergence rather than a direct Conti-cohort-continuity case in the idiom of OAK-S27 Black Basta or OAK-S28 Royal/BlackSuit; the lineage relationship is partial-codebase-derivative-with-distinct-operator-cohort rather than full cohort-continuity.
Active
active — Akira-branded operations continued through 2024 and into 2025 with sustained leak-site cadence and over 250 confirmed victim organisations through early 2024 per the April 2024 CISA / FBI / EC3 / NCSC-NL joint advisory AA24-109A ([cisaaa24109a]); the brand had not been subjected to a government takedown comparable to Operation Cronos (LockBit) or the December 2023 ALPHV action as of v0.1, and remains an active-detection target. Recorded Future / Coveware tracking placed Akira in the top-five ransomware brands by leak-site postings through 2024.
First observed
2023-03 (Akira-branded operations debuted March 2023 with the Windows C++ encryptor; the Rust-language Linux / VMware ESXi variant followed in April–May 2023, mirroring the broader RaaS-sector pivot to Rust-implemented hypervisor variants established by ALPHV / BlackCat).
Used by Groups
OAK-G16 Akira (primary operator cluster — drafted in parallel with this Software entry; the operator cohort is tracked at cluster level rather than as a named-individual operator, with no senior-leadership indictment or OFAC designation as of v0.1). Affiliate-side cross-use spans the broader post-Conti / post-ALPHV affiliate diaspora; Avast's June 2023 decryptor release ([avast2023akira]) and the subsequent operator response (encryptor rewrites to nullify the decryption flaw) is the principal documented disruption event in the brand's history short of a takedown.
Host platforms
Windows (primary, all enterprise-server variants, C++-authored codebase with partial structural similarities to Conti v3 documented by Sophos and Avast); Linux / VMware ESXi (a Rust-language variant emerged April–May 2023 under the temporary "Megazord" naming before consolidation back to the Akira brand). The dual-language architecture — C++ Windows + Rust ESXi/Linux — mirrors the ALPHV-influenced sector-wide pattern of Rust-for-cross-platform-hypervisor-variants while retaining C++ for the Windows codebase, a hybrid pattern that became more common across 2023–2024 RaaS emergences.
Observed Techniques
OAK-T7.001 (mixer-routed-hop, used for Akira-affiliate ransom proceeds 2023 with Sinbad pre-takedown the principal venue per Chainalysis tracking; post-Sinbad-takedown rotation onto smaller mixer infrastructure observed); OAK-T7.002 (CEX deposit-address layering, the post-2023 default with Garantex (OAK-G03) named in industry-forensic reporting as a recurring Akira-affiliate off-ramp consistent with the broader Russian-speaking-RaaS-cohort laundering pattern); OAK-T8.001 (common-funder cluster reuse, used for Akira-affiliate-cohort tracking and for documenting the partial-overlap signals with broader Conti-adjacent affiliate clusters per Chainalysis cross-cohort analysis).

Description

Akira is the ransomware encryptor codebase and brand maintained by a Russian-speaking operator cohort from March 2023 onward, emerging in the post-Conti / post-Hive cohort-dispersal landscape with a partial-codebase-derivative relationship to the Conti v3 leaked source and an operating model that combined the dual-language architecture (C++ Windows + Rust ESXi/Linux) increasingly common across 2023-emergent RaaS brands. From a defender perspective Akira occupies the same encryption-and-extortion functional role that Conti occupied 2020–2022 — large-enterprise targeting, double-extortion architecture (encryption plus data-theft-and-publication), VMware-ESXi-targeted hypervisor variant, leak-site-and-negotiation-portal infrastructure — with a particular targeting profile concentrated on small-and-mid-enterprise organisations across U.S., EMEA, and APAC critical-infrastructure verticals (manufacturing, healthcare, education, professional services).

The encryptor's distinguishing technical features include the leak-site's deliberate retro-1980s green-on-black terminal aesthetic (the most-recognisable surface signature of the brand), a partial-encryption mode for speed-versus-stealth tradeoff, ChaCha20-RSA hybrid encryption (the Windows variant) and the Rust-implemented ESXi variant's standard cross-platform Rust ransomware tooling, and a callback-to-leak-site negotiation-portal mechanism that mirrors the broader RaaS-sector double-extortion architecture. The June 2023 Avast decryptor release ([avast2023akira]) — one of the few public-record cases of a major-brand RaaS encryptor having a decryption-flaw publicly weaponised by an antivirus vendor — disrupted approximately 2 months of the brand's victim-recovery economics before the operator cohort responded with encryptor rewrites that nullified the flaw; the episode is a useful comparative reference for understanding the operator-response-cycle to public-decryptor-disclosure dynamics in the modern RaaS sector.

The April 2024 CISA / FBI / EC3 / NCSC-NL joint advisory AA24-109A ([cisaaa24109a]) is the canonical confirmed-grade institutional-attribution document for the brand, documenting over 250 victim organisations through early 2024 and identifying the operator cohort's tradecraft fingerprints across initial-access, lateral-movement, and ransom-payment phases. The four-government joint-advisory format (U.S. CISA / FBI, European Cybercrime Centre, Netherlands NCSC) is structurally distinctive — broader than the single-or-dual-government joint-advisory format typical of the OAK-S23 / S24 / S27 / S28 reference advisories — and reflects Akira's geographic spread and the multi-jurisdiction coordination that the cohort attracted by 2024.

The family's role in the Russian-speaking-cybercrime-ecosystem monetization chain is the encryption-and-extortion node feeding Russian-speaking-cluster laundering venues — Garantex (OAK-G03) is named in industry-forensic reporting as a recurring affiliate off-ramp, mirroring the broader post-Conti affiliate-cohort laundering pattern. Akira's deployment-frequency-versus-payment-volume profile is biased toward the small-and-mid-enterprise end of the RaaS-victim spectrum (lower per-incident ransom averages than ALPHV or LockBit's enterprise-focused profile, but a higher victim-count cadence), which produces a distinct on-chain signature: more wallets, smaller individual flows, but the same downstream routing topology as the higher-profile peers.

Observed examples

  • CISA AA24-109A campaign cohort (March 2023 – early 2024). The advisory documents over 250 named-and-unnamed Akira victim organisations across U.S., European, and APAC critical-infrastructure sectors with manufacturing, education, financial services, and healthcare verticals prominently called out; over $42M in approximated extortion revenue through the advisory's reference period. Confirmed-grade aggregate per [cisaaa24109a].
  • Stanford University incident (October 2023). Akira-claimed deployment against Stanford University's Department of Public Safety; data published on the Akira leak site after non-payment; one of the higher-profile U.S.-academic-sector incidents of 2023. Confirmed-grade per Stanford's own incident-disclosure and Akira leak-site posting.
  • Nissan Australia incident (December 2023). Akira deployment against Nissan's Australia and New Zealand subsidiary; data published on the Akira leak site; one of the more-prominent APAC-region incidents in the 2023 cohort. Confirmed-grade per Nissan's own incident-disclosure.
  • Avast decryptor episode (June 2023). Avast Threat Labs published a free decryptor for Akira-encrypted files exploiting a flaw in the encryptor's key-generation routine; the decryptor was operational against approximately 2 months of Akira-encrypted-file builds before the operator cohort responded with encryptor rewrites that nullified the flaw. Confirmed-grade per [avast2023akira] and subsequent industry reporting.
  • OAK on-chain example surface. No OAK examples/ entry exists for Akira-binary specifically as of v0.1; the Akira-to-Garantex chain documented in industry-forensic reporting is the strongest candidate for a future OAK example entry showing the OAK-S33-binary × OAK-G03-Garantex × T7.002 worked example, structurally parallel to the Conti / Black-Basta / Royal-BlackSuit chains.

Detection / attribution signals

Defenders should treat Akira detection as a host-layer + on-chain-layer joint problem with the dual-language Windows-C++-plus-Rust-ESXi architecture and the Conti-v3-partial-derivative codebase as the principal technical fingerprints:

  • Host-layer process-tree fingerprints — characteristic file-extension changes (.akira extension on encrypted files, with some Megazord-era ESXi variants using .powerranges and other temporary extensions); ransom-note filenames (akira_readme.txt per-folder); C++-Windows-binary signature with partial structural similarities to Conti v3 documented by Sophos and Avast; Rust-ESXi-variant signature (the Rust-runtime-symbol pattern is the coarse first-pass indicator); ChaCha20-RSA hybrid encryption mode signature; ESXi-variant invokes the standard esxcli VM-shutdown sequence shared across post-2022 RaaS brands.
  • Pre-encryption tradecraft — initial access via Cisco VPN credential-brute-force (a defining 2023 Akira-affiliate vector — multiple incidents documented Cisco VPN appliances with single-factor authentication as the entry point), exploitation of CVE-2023-20269 (Cisco ASA / FTD VPN authentication bypass) and other VPN-appliance vulnerabilities; post-foothold deployment of Cobalt Strike (OAK-S37); credential theft via Mimikatz; lateral movement via PsExec and WMI.
  • Network-layer telemetry — Cobalt Strike post-exploitation deployment after VPN-credential-foothold; data-exfiltration to operator-controlled cloud-storage staging (Mega.io, rclone-to-S3); leak-site negotiation-portal access patterns; Akira leak-site infrastructure has rotated multiple times across 2023–2024 with the retro-1980s-terminal visual identity persistent across rotations.
  • On-chain-layer signatures (the OAK-relevant signal) — Akira affiliate-controlled ransom-payment wallets exhibit common-funder cluster reuse (OAK-T8.001) within the affiliate cohort; downstream routing through Garantex (OAK-G03) is documented as a recurring affiliate off-ramp; the per-incident ransom volumes are biased toward the small-and-mid-enterprise end of the spectrum (smaller individual flows but higher cadence than enterprise-focused peers), producing a distinct on-chain signature.
  • CTI vendor coverage — Sophos (sustained "State of Ransomware" reporting and per-incident write-ups, plus the canonical Conti-v3-partial-derivative codebase analysis), Avast Threat Labs (the June 2023 decryptor release and subsequent encryptor-rewrite tracking), Mandiant (Akira intrusion-set tracking and the broader post-Conti cohort-emergence framing), Microsoft Threat Intelligence (Akira / Storm-class tracking), Trend Micro (continuous version-by-version analysis), Recorded Future (Insikt Group sustained Akira reporting), Chainalysis and TRM Labs (on-chain affiliate-cluster tracking).

Note: omit specific file hashes from this entry. Defenders should consume current IOCs from CISA AA24-109A and live CTI-vendor feeds named above.

Citations

  • [cisaaa24109a] — CISA / FBI / EC3 / NCSC-NL joint advisory AA24-109A on Akira ransomware, April 18, 2024. (NEW citation — see summary.)
  • [avast2023akira] — Avast Threat Labs Akira decryptor release and technical analysis, June 2023. (NEW citation — see summary.)
  • [sophosakira2023] — Sophos Akira tradecraft and Conti-v3-partial-derivative codebase analysis. (NEW citation — see summary.)
  • [mandiantakira2023] — Mandiant Akira intrusion-set tracking and post-Conti cohort-emergence framing. (NEW citation — see summary.)
  • [trendmicroakira2023] — Trend Micro Akira version-by-version analysis and Megazord-Rust-variant documentation. (NEW citation — see summary.)
  • [chainalysisakira2024] — Chainalysis Akira-attributable ransom-payment-volume tracking and affiliate-cluster analysis. (NEW citation — see summary.)
  • [ofac2022garantex] — Treasury OFAC Garantex designation press release; broader Russian-speaking-RaaS-cohort laundering-venue context.
  • [chainalysis2025ransomware] — Chainalysis 2024-recap ransomware report; cross-family context for the Akira volume distribution.

Discussion

On lineage as the central framing. OAK-S33's principal value as a Software entry is as a post-Conti-cohort-adjacent emergence with partial codebase derivation rather than a direct Conti-cohort-continuity case. Where Black Basta (OAK-S27) is a Conti-codebase-derivative-with-substantive-rewrites lineage and Royal/BlackSuit (OAK-S28) is a direct Conti-Zeon-fork lineage, Akira sits closer to independent operator emergence with opportunistic codebase-reuse from leaked Conti v3 source. The architectural distinction between full Conti-cohort-continuity (Black Basta, Royal/BlackSuit) and Conti-cohort-adjacent emergence (Akira) is useful for defender-side cohort-tracking work because it produces different cross-cluster wallet-cluster overlap signals at the OAK-T8.001 level — the Akira affiliate-cohort wallet topology shows partial overlap with broader post-Conti affiliate diaspora rather than the dense-overlap pattern characteristic of the direct-cohort-successor brands.

On the dual-language architecture. Akira's Windows-C++-plus-Rust-ESXi dual-language architecture is part of a broader 2023-emergent sector pattern of hybrid-codebase RaaS designs (LockBit's NG-Dev Rust rewrite was contemporaneous-but-pre-deployment; ALPHV's full-Rust architecture was the 2021 pioneer; multiple Conti-successor brands followed Akira's hybrid pattern in 2023–2024). The architectural differences between full-Rust (ALPHV), C++-Windows-only (Conti, Black Basta), and dual-language hybrid (Akira) provide a useful comparative reference for understanding the spectrum of language-and-platform tradeoffs available to RaaS encryptor developers as the Rust-language ecosystem matured.

On the Avast-decryptor episode and the operator-response-cycle. The June 2023 Avast decryptor release is one of the few public-record cases of a major-brand RaaS encryptor having a decryption-flaw publicly weaponised by an antivirus vendor; the Akira operator response — encryptor rewrites within approximately 2 months that nullified the flaw — is a useful comparative reference for understanding the operator-response-cycle to public-decryptor-disclosure dynamics. Comparable episodes include the FBI's December 2023 ALPHV decryptor release (which recovered files for approximately 500 victims before ALPHV operators rebuilt infrastructure) and the multiple Conti-era-pre-2022 decryptor releases by various AV vendors. The cycle-time of operator-response is a behavioural signal in its own right: faster response-cycles correlate with stronger operator-side development capacity and are diagnostic of the brand's operational maturity.

On the OAK Software-vs-Group split. OAK-S33 (this entry) is the Akira encryptor codebase and brand; OAK-G16 (drafted in parallel) is the Akira operator cluster. The split mirrors the OAK-S23 / OAK-G05 LockBit pattern; the principal asymmetry is that the Akira operator cluster has neither named-defendant indictment (LockBit / Khoroshev architecture) nor OFAC institutional-cluster designation (Garantex / Royal-BlackSuit architecture) as of v0.1, with attribution architecture relying on the four-government CISA / FBI / EC3 / NCSC-NL joint advisory and CTI-vendor cluster-level tracking. This attribution-architecture-thinness is itself diagnostic — Akira represents the typical attribution surface for a 2023–2024-emergent RaaS brand before sufficient enforcement-tempo accumulates to produce named-defendant or institutional-cluster designations.

On takedown / disruption history. Akira has not been subjected to a government takedown comparable to Operation Cronos (LockBit), the December 2023 ALPHV action, or the August 2023 Qakbot takedown; the Avast decryptor episode of June 2023 is the principal disruption event in the brand's history short of a takedown. The brand's continued operations through 2024 and into 2025 reflect the structural challenge of disrupting a Russian-jurisdiction-based operator cohort without the equivalent of the Khoroshev-naming / Operation-Cronos-infrastructure-seizure surface that drove the LockBit collapse, combined with Akira's geographic-and-victim-vertical diffusion that disperses enforcement-pressure across multiple jurisdictions rather than concentrating it at any single victim-side political-attention point.

Techniques observed (3)

Used by