Akira

APT / StateG1024 ↗
Techniques (MITRE ATT&CK)17
SourceMITRE ATT&CK
0
Also known as:GOLD SAHARAHowling ScorpiusPUNK SPIDER

Vexday analysis

Akira é uma entidade de implantação de ransomware ativa desde pelo menos março de 2023, rastreada pelo MITRE ATT&CK sob o identificador G1024 e também conhecida pelos nomes GOLD SAHARA, PUNK SPIDER e Howling Scorpius. O grupo utiliza credenciais comprometidas para acessar mecanismos de acesso externo com fator único de autenticação, como VPNs, e emprega ferramentas publicamente disponíveis para movimentação lateral nos ambientes comprometidos. Suas operações seguem o modelo de "dupla extorsão", no qual dados são exfiltrados antes da criptografia e a publicação dos arquivos é ameaçada caso o resgate não seja pago; variantes do ransomware são capazes de atingir sistemas Windows e hipervisores VMware ESXi. Com 17 técnicas documentadas no MITRE ATT&CK e 19 vítimas identificadas no Brasil, o grupo representa uma ameaça concreta ao ambiente corporativo brasileiro.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity39
Impact: High
T1059.001T1133T1558T1018T1213.002T1567.002EXECExecutionPowerShellPERSPersistenceExternal RemoteServicesCREDCredential accessSteal or ForgeKerberos TicketsDISCDiscoveryRemote SystemDiscoveryCOLLCollectionSharepointEXFILExfiltrationExfiltration toCloud StorageIMPACTImpactData Encrypted forImpact

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 17

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Impact and victims

The group Akira has 22 known ransomware victims. See the most affected sectors and countries and recent victims.

22known victims
22in Brazil
8sectors hit
Most attacked sectors
Manufacturing5
Retail & E-Commerce4
Professional Services3
Transportation2
Technology2
Energy & Utilities2
Healthcare1
Other1
Most affected countries
🇧🇷 Brasil22
Recent victims
Javep ChevroletRetail & E-Commerce · BR · 2026-09-17
VettaTechnology · BR · 2026-09-17
Javep ChevroletRetail & E-Commerce · BR · 2026-09-07
Dress ToRetail & E-Commerce · BR · 2025-04-24
D'GranelTransportation · BR · 2025-04-16
HelborOther · BR · 2025-03-26
Plaza Brasília HotéisHospitality · BR · 2025-03-25
PrimaverasRetail & E-Commerce · BR · 2025-02-14
Mac JeeTechnology · BR · 2025-02-09
mielectric.com.brManufacturing · BR · 2025-02-04
mipa.com.brManufacturing · BR · 2025-02-04
CapesespHealthcare · BR · 2025-01-10
Metalmatrix ClampsManufacturing · BR · 2025-01-10
A GeradoraEnergy & Utilities · BR · 2024-12-17
Diferencial EnergiaEnergy & Utilities · BR · 2024-12-16

Known infrastructure 116

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

urlhttp://92.127.156.174:8880/master.exeMimiKatzthreatfox
urlhttp://92.119.157.113:8000/aaAkiraurlhaus
urlhttp://92.119.157.113:8000/arm7Akiraurlhaus
md5_hashfec27228340485485f6902f8759bbd62MimiKatzthreatfox
sha1_hash07b35a3b431e653ddcf36cecd49793d538e2aa79MimiKatzthreatfox
sha256_hashf9d53fdcc12d548e6c9bd395642f30d2b2c6a9a4204bc0948badf8a7c571c072MimiKatzthreatfox
md5_hashcb3ac44312acae80a626ba1aa593f4deAkirathreatfox
md5_hashc12dde993b1954bb7a890e0d6a3c1314Akirathreatfox
md5_hash9b3dce50e1056e6eca0faee733c33f35Akirathreatfox
md5_hash904613f59987b5ebbc3e7d94b1390420Akirathreatfox
md5_hash9a7af0a766f7717d478c94414b15d25eAkirathreatfox
md5_hashf2bab102784860e65cd488387e42ca50Akirathreatfox
md5_hashbe6010d8bddef29ebbf3c8bb28f19517Akirathreatfox
md5_hash69446d7192ce7e5737bd9f7cbc7ca74aAkirathreatfox
md5_hash1c302704a76e2effc99f2d5e339d7f64Akirathreatfox
md5_hashf1e9419110b9f316c070eca39bea63d6Akirathreatfox
md5_hash266f33db148efc6ea7f978a246d36663Akirathreatfox
md5_hash251af0f2bea6c39064e162eac3b99ed6Akirathreatfox
md5_hash7d31b4d8fa391abaf49bf2c36d33fea2Akirathreatfox
md5_hash335d1205e666a401cc9ae6525a66546dAkirathreatfox
md5_hashcf135dac1f6d5c72cb2f361aad02591fAkirathreatfox
md5_hasha61ecd4bce5b291686756e7f1cda5c7bAkirathreatfox
md5_hashba9e9d8577544204e544d91a4cfbed9bAkirathreatfox
md5_hash561a13e7c71a8ebd4db51d04e61ba1abAkirathreatfox
md5_hash6b96b2e3cbd523607816524e67c36539Akirathreatfox
md5_hashe48e6c4a26379e2cf4a8e8c9a59ef094Akirathreatfox
md5_hash64622cb996b115fac71477650db0bb90Akirathreatfox
md5_hashfe609cbd263e01a51c53ce0651ad0adeAkirathreatfox
md5_hash432fdcf8fc43c3871c3346bb2aeb3de2Akirathreatfox
md5_hash0a52eca4d42889d0b3d21de101d4bea6Akirathreatfox

+116 indicators in total. See them all on the IOCs page.

Akira uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →