Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ Akira

🌐Akira

🌐 Akira is a tracked threat actor in the Clankerusecase corpus. Attributed to ??. Primary motivation: Criminal. We map 26 detection use cases to this actor across 59 MITRE ATT&CK techniques, with 4 threat-intel articles citing them. Active in our corpus from 2025-12-16 to 2026-07-10.

crit 4
View full actor card → All threat actors MITRE ATT&CK group spec (G1024) ↗
26Use cases
4Articles
59Techniques
3IOCs

Known aliases

Akira ransomwareAkiraGOLD SAHARAPUNK SPIDERHowling Scorpius

Top techniques

All other tracked techniques

T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1014 · RootkitT1018 · Remote System DiscoveryT1021.001 · Remote Desktop ProtocolT1027 · Obfuscated Files or InformationT1027.001 · Binary PaddingT1027.002 · Software PackingT1027.005 · Indicator Removal from ToolsT1027.009 · Embedded PayloadsT1036.005 · Match Legitimate Resource Name or LocationT1037.001 · Logon Script (Windows)T1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1053.005 · Scheduled TaskT1055 · Process InjectionT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1068 · Exploitation for Privilege EscalationT1070.001 · T1070.001T1070.004 · File DeletionT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1078 · Valid AccountsT1090 · ProxyT1133 · External Remote ServicesT1140 · Deobfuscate/Decode Files or InformationT1190 · Exploit Public-Facing ApplicationT1195.002 · Compromise Software Supply ChainT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1213.002 · SharepointT1218 · System Binary Proxy ExecutionT1219 · Remote Access ToolsT1482 · Domain Trust DiscoveryT1489 · Service StopT1490 · Inhibit System RecoveryT1531 · Account Access RemovalT1539 · Steal Web Session CookieT1543.003 · Windows ServiceT1555.003 · Credentials from Web BrowsersT1558 · Steal or Forge Kerberos TicketsT1560.001 · Archive via UtilityT1562.001 · T1562.001T1562.004 · T1562.004T1562.006 · T1562.006T1562.009 · T1562.009T1566 · PhishingT1566.001 · Spearphishing AttachmentT1567.002 · Exfiltration to Cloud StorageT1569.002 · Service ExecutionT1657 · Financial TheftT1685 · Disable or Modify Tools

Detection use cases (26)

Akira pre-encryption recovery inhibition: WMI/PowerShell shadow-copy wipe + Veeam backup service kill AI · profile SΣDD Akira double-extortion staging: Rclone/WinSCP bulk exfil to Mega/cloud before encryption AI · profile SDD The Gentlemen ransomware scheduled task named gentlemen* Bespoke GentleKiller BYOVD: ThrottleBlood.sys vulnerable driver load (CVE-2025-7771) Bespoke GentleKiller EDR-killer binaries Allpatch2.exe / All.exe execution Bespoke The Gentlemen wevtutil clearing of Security/System/Application event logs Bespoke The Gentlemen internal reconnaissance via Advanced IP Scanner Bespoke The Gentlemen SystemBC C2 beacon to known operator IPs Bespoke The Gentlemen pre-encryption Volume Shadow Copy deletion Bespoke The Gentlemen Go encryptor mass file rename to actor extensions Bespoke Beaconing — periodic outbound to small set of destinations Internal Network connections to article IPs / domains Internal Infostealer — non-browser process accessing browser cookie/login DBs Internal Asset exposure — vulnerability matches article CVE(s) Internal 1Password impossible-travel sign-in MITRE match AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation MITRE match Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request MITRE match Internet-Exposed AI Agent/LLM Service Spawns Shell or LOLBin After Inbound Connection MITRE match Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution MITRE match Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write MITRE match Atlassian administrator impersonating user MITRE match Auth0 anomalous attack-protection event spike MITRE match AWS Console login without MFA + impossible travel MITRE match

Threat-intel articles (4)

Tracked indicators

IP addresses (3)

193.233.202.17 45.86.230.112 77.110.122.137

CVEs (7)

CVE-2023-27532 CVE-2024-37085 CVE-2024-55591 CVE-2025-32433 CVE-2025-33073 CVE-2025-55182 CVE-2025-7771