Actor · RaaS · since 2023
Akira: the ransomware that walks in through the VPN
Active since March 2023, Akira is one of the top three ransomware threats to Canada in 2024 according to the Cyber Centre. Entry points, incidents and controls.
- Model
- RaaS · since 2023-03
- Ways in
- VPN without MFA · SonicWall CVE-2024-40766 · Cisco ASA CVEs · Veeam Backup CVEs · Spear phishing
- Targets
- SMBs · Education · Manufacturing · Telecommunications · ESXi and Nutanix AHV
- Official advisories
- AA24-109A
By Sentrix · Published 2026-09-20
Akira is the name incident response teams have seen most often in North America for two years. Its playbook is brutally simple: a remote access without multi-factor authentication, exfiltration within hours, encryption of the hypervisors.
Who they are
According to joint advisory AA24-109A, published on April 18, 2024 and revised on November 13, 2025 by the FBI, CISA, Europol and European cybercrime units, Akira has been hitting organizations since March 2023, first on Windows, with a Linux variant as early as April 2023 and a Rust encryptor named Megazord from August 2023. The same advisory puts the ransom proceeds at approximately 244.17 million US dollars as of late September 2025.
The Canadian Centre for Cyber Security, in its 2025-2027 outlook published on January 28, 2026, describes Akira as a RaaS group very likely connected to the disbanded Conti group, operating two ransomware variants and practicing double extortion. That report lists Akira among the top three ransomware threats to Canada in 2024, with Play and Medusa. The Sophos Active Adversary Report 2026, built on cases handled between November 2024 and October 2025, names Akira and Qilin as the most active ransomware brands, with Akira present in 22% of incidents.
How they get in
Advisory AA24-109A is unambiguous: the first door is a VPN service without multi-factor authentication. Then come known vulnerabilities on edge devices and backup servers, including CVE-2020-3259 and CVE-2023-20269 on Cisco, CVE-2024-40766 on SonicWall and CVE-2023-27532 and CVE-2024-40711 on Veeam, followed by spear phishing, RDP and brute force.
Once inside, affiliates exfiltrate with FileZilla, WinSCP, RClone or MEGA and keep access with AnyDesk, RustDesk or Cloudflare and Ngrok tunnels, according to the same advisory, which notes exfiltration completed within about two hours of initial access in some incidents. Encryption targets Windows, Linux, VMware ESXi and, since a June 2025 incident documented in the advisory, Nutanix AHV. The Canadian Centre for Cyber Security reports victims in manufacturing and telecommunications in Canada.
What they have done
- April 2023: deployment of a Linux variant a few weeks after the first Windows attacks, according to advisory AA24-109A.
- June 2025: first observed attack on the Nutanix AHV hypervisor, reported in the revision of advisory AA24-109A.
- July and August 2025: exploitation campaign against CVE-2024-40766 on SonicWall firewalls, described by Darktrace, with a detection on August 20, 2025 at a US customer and about 2 GiB of data leaving the network before containment.
- Late September 2025: approximately 244.17 million US dollars in cumulative ransoms, according to advisory AA24-109A.
What stops them
The mitigations of advisory AA24-109A, mapped to the frameworks auditors check.
- Phishing-resistant MFA on all remote access, VPN and webmail first. ISO 27001:2022 A.8.5, SOC 2 CC6.1.
- Patch known exploited vulnerabilities on edge devices and backup servers, then rotate the credentials that may have leaked before the patch. ISO 27001:2022 A.8.8, SOC 2 CC7.1.
- Encrypted, offline backups with tested restores, including for ESXi and Nutanix. ISO 27001:2022 A.8.13, SOC 2 A1.2.
- Network segmentation so that a compromised workstation cannot reach hypervisors and backups. ISO 27001:2022 A.8.22.
- Monitoring of remote access tools and outbound transfers: AnyDesk, RustDesk, RClone and MEGA have no business on a server without approval. ISO 27001:2022 A.8.16, SOC 2 CC7.2.
- Review of administrative accounts and least privilege, because initial access is never the end of the story. ISO 27001:2022 A.5.15 and A.8.2.
Sources
- CISA, FBI and partners, #StopRansomware: Akira Ransomware, AA24-109A (April 18, 2024, revised November 13, 2025)
- Canadian Centre for Cyber Security, Ransomware Threat Outlook 2025-2027 (January 28, 2026)
- Darktrace, Inside Akira's SonicWall campaign (October 9, 2025)
- Sophos, Active Adversary Report 2026 (press release)
Frequently asked questions
- Does Akira really target Canada?
- Yes. The Canadian Centre for Cyber Security names Akira among the top three ransomware threats to Canada in 2024, with Play and Medusa, and reports victims in manufacturing and telecommunications in Canada. Advisory AA24-109A adds that the group mostly hits small and medium-sized organizations, with a preference for educational institutions, which describes a large share of the Canadian economy.
- What is the link between Akira and Conti?
- The Canadian Centre for Cyber Security assesses that Akira is very likely connected to the disbanded Conti group. That does not make it a mere continuation: Akira has its own encryptors, including a Rust variant named Megazord that appeared in August 2023 according to advisory AA24-109A, and its own affiliate program. The link mostly explains the experience of the operators.
- Is a patched VPN enough against Akira?
- No. Advisory AA24-109A puts VPN services without multi-factor authentication first among entry routes, ahead of vulnerabilities. Darktrace observed affiliates exploiting CVE-2024-40766 on SonicWall devices in August 2025, almost a year after the patch, often with credentials stolen before the update. You have to patch, rotate the credentials, then enforce MFA on the service.
Let's talk about your compliance program.
Last updated: 2026-09-20
