Software · OAK-S33 · ransomware
OAK-S33 — Akira ransomware
Description
Akira is the ransomware encryptor codebase and brand maintained by a Russian-speaking operator cohort from March 2023 onward, emerging in the post-Conti / post-Hive cohort-dispersal landscape with a partial-codebase-derivative relationship to the Conti v3 leaked source and an operating model that combined the dual-language architecture (C++ Windows + Rust ESXi/Linux) increasingly common across 2023-emergent RaaS brands. From a defender perspective Akira occupies the same encryption-and-extortion functional role that Conti occupied 2020–2022 — large-enterprise targeting, double-extortion architecture (encryption plus data-theft-and-publication), VMware-ESXi-targeted hypervisor variant, leak-site-and-negotiation-portal infrastructure — with a particular targeting profile concentrated on small-and-mid-enterprise organisations across U.S., EMEA, and APAC critical-infrastructure verticals (manufacturing, healthcare, education, professional services).
The encryptor's distinguishing technical features include the leak-site's deliberate retro-1980s green-on-black terminal aesthetic (the most-recognisable surface signature of the brand), a partial-encryption mode for speed-versus-stealth tradeoff, ChaCha20-RSA hybrid encryption (the Windows variant) and the Rust-implemented ESXi variant's standard cross-platform Rust ransomware tooling, and a callback-to-leak-site negotiation-portal mechanism that mirrors the broader RaaS-sector double-extortion architecture. The June 2023 Avast decryptor release ([avast2023akira]) — one of the few public-record cases of a major-brand RaaS encryptor having a decryption-flaw publicly weaponised by an antivirus vendor — disrupted approximately 2 months of the brand's victim-recovery economics before the operator cohort responded with encryptor rewrites that nullified the flaw; the episode is a useful comparative reference for understanding the operator-response-cycle to public-decryptor-disclosure dynamics in the modern RaaS sector.
The April 2024 CISA / FBI / EC3 / NCSC-NL joint advisory AA24-109A ([cisaaa24109a]) is the canonical confirmed-grade institutional-attribution document for the brand, documenting over 250 victim organisations through early 2024 and identifying the operator cohort's tradecraft fingerprints across initial-access, lateral-movement, and ransom-payment phases. The four-government joint-advisory format (U.S. CISA / FBI, European Cybercrime Centre, Netherlands NCSC) is structurally distinctive — broader than the single-or-dual-government joint-advisory format typical of the OAK-S23 / S24 / S27 / S28 reference advisories — and reflects Akira's geographic spread and the multi-jurisdiction coordination that the cohort attracted by 2024.
The family's role in the Russian-speaking-cybercrime-ecosystem monetization chain is the encryption-and-extortion node feeding Russian-speaking-cluster laundering venues — Garantex (OAK-G03) is named in industry-forensic reporting as a recurring affiliate off-ramp, mirroring the broader post-Conti affiliate-cohort laundering pattern. Akira's deployment-frequency-versus-payment-volume profile is biased toward the small-and-mid-enterprise end of the RaaS-victim spectrum (lower per-incident ransom averages than ALPHV or LockBit's enterprise-focused profile, but a higher victim-count cadence), which produces a distinct on-chain signature: more wallets, smaller individual flows, but the same downstream routing topology as the higher-profile peers.
Observed examples
- CISA AA24-109A campaign cohort (March 2023 – early 2024). The advisory documents over 250 named-and-unnamed Akira victim organisations across U.S., European, and APAC critical-infrastructure sectors with manufacturing, education, financial services, and healthcare verticals prominently called out; over $42M in approximated extortion revenue through the advisory's reference period. Confirmed-grade aggregate per
[cisaaa24109a]. - Stanford University incident (October 2023). Akira-claimed deployment against Stanford University's Department of Public Safety; data published on the Akira leak site after non-payment; one of the higher-profile U.S.-academic-sector incidents of 2023. Confirmed-grade per Stanford's own incident-disclosure and Akira leak-site posting.
- Nissan Australia incident (December 2023). Akira deployment against Nissan's Australia and New Zealand subsidiary; data published on the Akira leak site; one of the more-prominent APAC-region incidents in the 2023 cohort. Confirmed-grade per Nissan's own incident-disclosure.
- Avast decryptor episode (June 2023). Avast Threat Labs published a free decryptor for Akira-encrypted files exploiting a flaw in the encryptor's key-generation routine; the decryptor was operational against approximately 2 months of Akira-encrypted-file builds before the operator cohort responded with encryptor rewrites that nullified the flaw. Confirmed-grade per
[avast2023akira]and subsequent industry reporting. - OAK on-chain example surface. No OAK
examples/entry exists for Akira-binary specifically as of v0.1; the Akira-to-Garantex chain documented in industry-forensic reporting is the strongest candidate for a future OAK example entry showing the OAK-S33-binary × OAK-G03-Garantex × T7.002 worked example, structurally parallel to the Conti / Black-Basta / Royal-BlackSuit chains.
Detection / attribution signals
Defenders should treat Akira detection as a host-layer + on-chain-layer joint problem with the dual-language Windows-C++-plus-Rust-ESXi architecture and the Conti-v3-partial-derivative codebase as the principal technical fingerprints:
- Host-layer process-tree fingerprints — characteristic file-extension changes (
.akiraextension on encrypted files, with some Megazord-era ESXi variants using.powerrangesand other temporary extensions); ransom-note filenames (akira_readme.txtper-folder); C++-Windows-binary signature with partial structural similarities to Conti v3 documented by Sophos and Avast; Rust-ESXi-variant signature (the Rust-runtime-symbol pattern is the coarse first-pass indicator); ChaCha20-RSA hybrid encryption mode signature; ESXi-variant invokes the standardesxcliVM-shutdown sequence shared across post-2022 RaaS brands. - Pre-encryption tradecraft — initial access via Cisco VPN credential-brute-force (a defining 2023 Akira-affiliate vector — multiple incidents documented Cisco VPN appliances with single-factor authentication as the entry point), exploitation of CVE-2023-20269 (Cisco ASA / FTD VPN authentication bypass) and other VPN-appliance vulnerabilities; post-foothold deployment of Cobalt Strike (OAK-S37); credential theft via Mimikatz; lateral movement via PsExec and WMI.
- Network-layer telemetry — Cobalt Strike post-exploitation deployment after VPN-credential-foothold; data-exfiltration to operator-controlled cloud-storage staging (Mega.io, rclone-to-S3); leak-site negotiation-portal access patterns; Akira leak-site infrastructure has rotated multiple times across 2023–2024 with the retro-1980s-terminal visual identity persistent across rotations.
- On-chain-layer signatures (the OAK-relevant signal) — Akira affiliate-controlled ransom-payment wallets exhibit common-funder cluster reuse (OAK-T8.001) within the affiliate cohort; downstream routing through Garantex (OAK-G03) is documented as a recurring affiliate off-ramp; the per-incident ransom volumes are biased toward the small-and-mid-enterprise end of the spectrum (smaller individual flows but higher cadence than enterprise-focused peers), producing a distinct on-chain signature.
- CTI vendor coverage — Sophos (sustained "State of Ransomware" reporting and per-incident write-ups, plus the canonical Conti-v3-partial-derivative codebase analysis), Avast Threat Labs (the June 2023 decryptor release and subsequent encryptor-rewrite tracking), Mandiant (Akira intrusion-set tracking and the broader post-Conti cohort-emergence framing), Microsoft Threat Intelligence (Akira / Storm-class tracking), Trend Micro (continuous version-by-version analysis), Recorded Future (Insikt Group sustained Akira reporting), Chainalysis and TRM Labs (on-chain affiliate-cluster tracking).
Note: omit specific file hashes from this entry. Defenders should consume current IOCs from CISA AA24-109A and live CTI-vendor feeds named above.
Citations
[cisaaa24109a]— CISA / FBI / EC3 / NCSC-NL joint advisory AA24-109A on Akira ransomware, April 18, 2024. (NEW citation — see summary.)[avast2023akira]— Avast Threat Labs Akira decryptor release and technical analysis, June 2023. (NEW citation — see summary.)[sophosakira2023]— Sophos Akira tradecraft and Conti-v3-partial-derivative codebase analysis. (NEW citation — see summary.)[mandiantakira2023]— Mandiant Akira intrusion-set tracking and post-Conti cohort-emergence framing. (NEW citation — see summary.)[trendmicroakira2023]— Trend Micro Akira version-by-version analysis and Megazord-Rust-variant documentation. (NEW citation — see summary.)[chainalysisakira2024]— Chainalysis Akira-attributable ransom-payment-volume tracking and affiliate-cluster analysis. (NEW citation — see summary.)[ofac2022garantex]— Treasury OFAC Garantex designation press release; broader Russian-speaking-RaaS-cohort laundering-venue context.[chainalysis2025ransomware]— Chainalysis 2024-recap ransomware report; cross-family context for the Akira volume distribution.
Discussion
On lineage as the central framing. OAK-S33's principal value as a Software entry is as a post-Conti-cohort-adjacent emergence with partial codebase derivation rather than a direct Conti-cohort-continuity case. Where Black Basta (OAK-S27) is a Conti-codebase-derivative-with-substantive-rewrites lineage and Royal/BlackSuit (OAK-S28) is a direct Conti-Zeon-fork lineage, Akira sits closer to independent operator emergence with opportunistic codebase-reuse from leaked Conti v3 source. The architectural distinction between full Conti-cohort-continuity (Black Basta, Royal/BlackSuit) and Conti-cohort-adjacent emergence (Akira) is useful for defender-side cohort-tracking work because it produces different cross-cluster wallet-cluster overlap signals at the OAK-T8.001 level — the Akira affiliate-cohort wallet topology shows partial overlap with broader post-Conti affiliate diaspora rather than the dense-overlap pattern characteristic of the direct-cohort-successor brands.
On the dual-language architecture. Akira's Windows-C++-plus-Rust-ESXi dual-language architecture is part of a broader 2023-emergent sector pattern of hybrid-codebase RaaS designs (LockBit's NG-Dev Rust rewrite was contemporaneous-but-pre-deployment; ALPHV's full-Rust architecture was the 2021 pioneer; multiple Conti-successor brands followed Akira's hybrid pattern in 2023–2024). The architectural differences between full-Rust (ALPHV), C++-Windows-only (Conti, Black Basta), and dual-language hybrid (Akira) provide a useful comparative reference for understanding the spectrum of language-and-platform tradeoffs available to RaaS encryptor developers as the Rust-language ecosystem matured.
On the Avast-decryptor episode and the operator-response-cycle. The June 2023 Avast decryptor release is one of the few public-record cases of a major-brand RaaS encryptor having a decryption-flaw publicly weaponised by an antivirus vendor; the Akira operator response — encryptor rewrites within approximately 2 months that nullified the flaw — is a useful comparative reference for understanding the operator-response-cycle to public-decryptor-disclosure dynamics. Comparable episodes include the FBI's December 2023 ALPHV decryptor release (which recovered files for approximately 500 victims before ALPHV operators rebuilt infrastructure) and the multiple Conti-era-pre-2022 decryptor releases by various AV vendors. The cycle-time of operator-response is a behavioural signal in its own right: faster response-cycles correlate with stronger operator-side development capacity and are diagnostic of the brand's operational maturity.
On the OAK Software-vs-Group split. OAK-S33 (this entry) is the Akira encryptor codebase and brand; OAK-G16 (drafted in parallel) is the Akira operator cluster. The split mirrors the OAK-S23 / OAK-G05 LockBit pattern; the principal asymmetry is that the Akira operator cluster has neither named-defendant indictment (LockBit / Khoroshev architecture) nor OFAC institutional-cluster designation (Garantex / Royal-BlackSuit architecture) as of v0.1, with attribution architecture relying on the four-government CISA / FBI / EC3 / NCSC-NL joint advisory and CTI-vendor cluster-level tracking. This attribution-architecture-thinness is itself diagnostic — Akira represents the typical attribution surface for a 2023–2024-emergent RaaS brand before sufficient enforcement-tempo accumulates to produce named-defendant or institutional-cluster designations.
On takedown / disruption history. Akira has not been subjected to a government takedown comparable to Operation Cronos (LockBit), the December 2023 ALPHV action, or the August 2023 Qakbot takedown; the Avast decryptor episode of June 2023 is the principal disruption event in the brand's history short of a takedown. The brand's continued operations through 2024 and into 2025 reflect the structural challenge of disrupting a Russian-jurisdiction-based operator cohort without the equivalent of the Khoroshev-naming / Operation-Cronos-infrastructure-seizure surface that drove the LockBit collapse, combined with Akira's geographic-and-victim-vertical diffusion that disperses enforcement-pressure across multiple jurisdictions rather than concentrating it at any single victim-side political-attention point.