
Ransomware isn't going away—it’s constantly evolving and remains one of the biggest threats to businesses worldwide. One name that has recently dominated the headlines is Akira Ransomware. Akira was first observed in the wild in March 2023 and quickly emerged as a significant Ransomware-as-a-Service (RaaS) operation.
The threat actor behind Akira is commonly tracked as the Akira ransomware group, also associated with the names Howling Scorpius, GOLD SAHARA, and PUNK SPIDER. Security researchers have identified several overlaps between Akira activity and Conti-affiliated threat actors, including cryptocurrency transactions associated with former Conti leadership. However, the exact organizational relationship between Akira and Conti remains subject to ongoing research, and the available evidence does not conclusively establish Akira as simply a direct rebrand of Conti.
Recently, we observed an Akira Ransomware variant in the wild. The analyzed sample is a native C++ binary.powershell.exe -Command "Get-WmiObject Win32_Shadowcopy | Remove-WmiObject"
The malware then begins encrypting files. Encrypted files are identified by the “.akira” extension appended to their original filenames. After encrypting the files, the ransomware drops a log file in its execution directory and places an akira_readme.txt ransom note in each directory containing encrypted files. The ransom note instructs victims to install the Tor Browser and follow the provided instructions to pay the ransom.
Following image shows the SonicWall Endpoint Security solution detecting and blocking malware during download, showing how it protects users when they try to download a malicious sample through a web browser or as an email attachment.
The following image shows the SonicWall Endpoint Security detecting the malware during suspicious command-line execution, as it attempts to launch PowerShell and delete Volume Shadow Copies using WMI.
The following image shows the SonicWall Endpoint Security detecting the malware through memory scanning.
The following figure shows the SonicWall Endpoint Security detecting the malware during image loading, before execution begins, when the user attempts to run the malicious file.
This threat is detected by SonicWall Capture ATP with RTDMI™, SonicWall Endpoint Security and the Capture Client endpoint solution.
Share This Article

An Article By
An Article By
Madhukar Waghmare
Software Dev Senior Engineer
Madhukar Waghmare
Software Dev Senior Engineer