Threat actor · all actors
AkiraG1024 criminal
aka Akira, GOLD SAHARA, PUNK SPIDER, Howling Scorpius, Storm-1567, Megazord
Last updated: 2026-08-20
About this actor
[Akira](https://attack.mitre.org/groups/G1024) is a ransomware variant and ransomware deployment entity active since at least March 2023.(Citation: Arctic Wolf Akira 2023) [Akira](https://attack.mitre.org/groups/G1024) uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement.(Citation: Arctic Wolf Akira 2023)(Citation: Secureworks GOLD SAHARA) [Akira](https://attack.mitre.org/groups/G1024) operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of [Akira](https://attack.mitre.org/software/S1129) ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with [Conti](https://attack.mitre.org/software/S0575) ransomware.(Citation: BushidoToken Akira 2023)(Citation: CISA Akira Ransomware APR 2024)(Citation: Cisco Akira Ransomware OCT 2024)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
Secureworkscolour-metal names
Palo Alto Unit 42constellation names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 24 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2023 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2023-20263 | 3.8 | 4.7 | 0.0048 | 2023-09-06 | see CVE |
T1018Remote System Discovery ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1027Obfuscated Files or Information ↗T1027.001Binary Padding ↗T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1078Valid Accounts ↗T1133External Remote Services ↗T1213Data from Information Repositories ↗T1213.002Sharepoint ↗T1219Remote Access Tools ↗T1482Domain Trust Discovery ↗T1486Data Encrypted for Impact ↗T1531Account Access Removal ↗T1558Steal or Forge Kerberos Tickets ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1567Exfiltration Over Web Service ↗T1567.002Exfiltration to Cloud Storage ↗T1657Financial Theft ↗T1685Disable or Modify Tools ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 18 / 24 | 75% |
CM-2 | 17 / 24 | 71% |
AC-3 | 16 / 24 | 67% |
AC-6 | 15 / 24 | 62% |
CM-6 | 15 / 24 | 62% |
CM-7 | 13 / 24 | 54% |
AC-2 | 12 / 24 | 50% |
SI-3 | 12 / 24 | 50% |
SI-7 | 12 / 24 | 50% |
RA-5 | 11 / 24 | 46% |
AC-5 | 10 / 24 | 42% |
CA-7 | 10 / 24 | 42% |
IA-2 | 10 / 24 | 42% |
AC-17 | 9 / 24 | 38% |
CM-5 | 9 / 24 | 38% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- INC Ransom 0.26
- Play 0.23
- Indrik Spider 0.22
- C0018 0.22
- ToddyCat 0.22
Active in same years
- Cinnamon Tempest 1.00
- MirrorFace 1.00
- Clop 1.00
Same category
- LAPSUS$ 1.00
- INC Ransom 1.00
- Play 1.00
- BlackByte 1.00
- ShinyHunters 1.00