Threat Research, Threat intelligence

SonicWall Endpoint Security in Action: Detecting Akira Ransomware

by Madhukar Waghmare

Introduction

Ransomware isn't going away—it’s constantly evolving and remains one of the biggest threats to businesses worldwide. One name that has recently dominated the headlines is Akira Ransomware.  Akira was first observed in the wild in March 2023 and quickly emerged as a significant Ransomware-as-a-Service (RaaS) operation. 

The threat actor behind Akira is commonly tracked as the Akira ransomware group, also associated with the names Howling Scorpius, GOLD SAHARA, and PUNK SPIDER. Security researchers have identified several overlaps between Akira activity and Conti-affiliated threat actors, including cryptocurrency transactions associated with former Conti leadership. However, the exact organizational relationship between Akira and Conti remains subject to ongoing research, and the available evidence does not conclusively establish Akira as simply a direct rebrand of Conti.

Recently, we observed an Akira Ransomware variant in the wild. The analyzed sample is a native C++ binary.
Figure_1_Malware_Compiler_Information.JPG
Figure 1: Malware Compiler Information
Akira primarily spreads through two attack vectors: weaponized email attachments targeting internal users and network intrusions exploiting vulnerabilities in corporate environments. Upon execution, the malware deletes Volume Shadow Copies by launching PowerShell with the following command, preventing their use for file recovery:

powershell.exe -Command "Get-WmiObject Win32_Shadowcopy | Remove-WmiObject"

The malware then begins encrypting files. Encrypted files are identified by the “.akira” extension appended to their original filenames. After encrypting the files, the ransomware drops a log file in its execution directory and places an akira_readme.txt ransom note in each directory containing encrypted files. The ransom note instructs victims to install the Tor Browser and follow the provided instructions to pay the ransom. 
Figure_2_Ransom_Note.JPG
Figure 2: Ransom Note
If the user opens the provided link in a Tor-based browser, it directs them to the Akira webpage, where they can interact with the Akira group’s interface.
Figure_3_Akira_webpage.jpg
Figure 3: Akira webpage
Preventing Ransomware Attacks with SonicWall Endpoint Security Solution
SonicWall continuously detects prominent threats targeting our customers and helps protect them against evolving threat actors. The following image shows the Akira Ransomware detection by the SonicWall Endpoint Security solution. 
Figure_4_Akira_detected_by_SonicWall_Endpoint_Security.JPG
Figure 4: Akira detected by SonicWall Endpoint Security
We are also sharing additional images showing the detection of Akira Ransomware at various stages, including download and execution. These images provide an overview of how SonicWall Endpoint Security detects and blocks the malware at different stages of its execution, helping protect users from potential threats.

Following image shows the SonicWall Endpoint Security solution detecting and blocking malware during download, showing how it protects users when they try to download a malicious sample through a web browser or as an email attachment.

Figure_5_On_Download_Detection_.JPG
Figure 5: On Download Detection

The following image shows the SonicWall Endpoint Security detecting the malware during suspicious command-line execution, as it attempts to launch PowerShell and delete Volume Shadow Copies using WMI. 

Figure_6_On_Command_Execution_Detection_.JPG
Figure 6: On Command Execution Detection

The following image shows the SonicWall Endpoint Security detecting the malware through memory scanning. 

Figure_7_In_Memory_Detection_.JPG
Figure 7: In-Memory Detection

The following figure shows the SonicWall Endpoint Security detecting the malware during image loading, before execution begins, when the user attempts to run the malicious file. 

Figure_8_On_Image_Load_Detection_.JPG
Figure 8: On Image Load Detection

This threat is detected by SonicWall Capture ATP with RTDMI™, SonicWall Endpoint Security and the Capture Client endpoint solution.

Share This Article

An Article By

Madhukar Waghmare

Software Dev Senior Engineer

Madhukar is a forward-thinking malware researcher and machine learning specialist with nearly a decade of experience in security research and research-driven programming. He is an expert in reverse engineering a wide range of malwares, analyzing infection chains and developing robust solutions to protect users.

Related Articles

  • Oracle HTTP & WebLogic Servers Proxy Plug-in Authentication Bypass
    Read More
  • Microsoft Security Bulletin Coverage for September 2026
    Read More