Back to Intelligence

AKIRA Ransomware Gang: 3 New Leak-Site Listings Across Manufacturing & Professional Services — Targeting Analysis & Detection Rules

SA
Security Arsenal Team
October 2, 2026
12 min read

Classification: TLP:CLEAR | Publication Date: 2026-10-02 | Source: ransomware.live leak-site monitoring | Nature of data: Unverified threat-actor claims

AKIRA Ransomware Gang: 3 New Leak-Site Listings Across Manufacturing & Professional Services

Executive Summary

Security Arsenal's dark web monitoring of the AKIRA ransomware gang's Tor-based leak site, aggregated via ransomware.live, identified 3 new victim listings published on 2026-10-01. The named organizations span Manufacturing, Professional Services, and Other sectors, with at least one US-based organization identified. All three listings are tagged MULTI-SOURCE, meaning two independent leak-site crawlers observed the gang make these claims.

Critical caveat: These are unverified accusations by a criminal organization. Inclusion on a leak site is not confirmation that any breach occurred. This briefing treats the claims as threat intelligence on AKIRA's current targeting posture — not as incident confirmation — and delivers detection engineering content so defenders can hunt for AKIRA's known tradecraft regardless of whether any specific claim is substantiated.

Organizations AKIRA has listed on its leak site:

OrganizationSector (as listed)CountryPublishedCorroboration
WesmarManufacturingUS2026-10-01MULTI-SOURCE
DPL GroupOtherNot disclosed2026-10-01MULTI-SOURCE
Krycler, Ervin, Taubman & KaminskyProfessional ServicesNot disclosed2026-10-01MULTI-SOURCE

Sourcing & Verification

  • 3 of 3 listings were independently observed by a second leak-site crawler (MULTI-SOURCE). 0 listings appear on a single source only.
  • MULTI-SOURCE corroboration confirms only that the threat actor published the claim. Inclusion in this briefing reflects AKIRA's allegation and is not confirmation of a breach. No corroboration tier in this dataset confirms a breach — only the named organization or its regulator can do that.
  • A named organization may dispute its listing, and a denial is likewise not proof the claim is false. Disclosure obligations vary by jurisdiction and incident type, and not every incident is reportable — neither silence nor denial settles the question.
  • Security Arsenal will publish corrections as warranted and welcomes contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — AKIRA

Aliases & lineage: AKIRA (also tracked as Akira ransomware). The operation emerged in March 2023 and is widely assessed by researchers to share code lineage and personnel overlap with the defunct Conti operation. AKIRA maintains separate Windows and Linux/ESXi encryptors and operates a dedicated Tor leak site.

Operating model: Ransomware-as-a-Service (RaaS). AKIRA recruits affiliates who conduct intrusion and deployment; the core group operates the leak site, negotiation infrastructure, and takes a revenue share (commonly estimated at 15–30% of ransom proceeds).

Ransom demands: Historically range from ~$200,000 to several million USD, scaled to victim revenue. AKIRA is known to negotiate and to publish staged partial data leaks to pressure victims.

Initial access methods (documented across campaigns):

  • Exploitation of VPN appliances lacking MFA (notably Cisco ASA/AnyConnect and SonicWall SSLVPN) — AKIRA's most consistent entry vector
  • Stolen credentials from infostealer logs and dark web markets
  • RDP brute force / exposed RDP
  • Phishing with macro-enabled documents and malicious loaders
  • Public-facing application exploitation (hypothesis-level linkage to edge-device CVEs — see Campaign Analysis)

Extortion model: Double extortion — data exfiltration precedes encryption, with leak-site publication as leverage. AKIRA typically exfiltrates via Rclone, FileZilla, and WinSCP to cloud storage or actor-controlled infrastructure.

Dwell time: Observed dwell time ranges from same-day detonation to roughly two weeks, with a median often cited around 3–7 days. AKIRA affiliates frequently move fast once VPN access is established — defenders may have hours, not days, between initial access and staging.

Signature tradecraft:

  • vssadmin delete shadows /all /quiet and wmic shadowcopy delete prior to encryption
  • PsExec and WMI for lateral movement
  • AnyDesk / RustDesk for persistence
  • Credential dumping via LSASS memory access and registry hive extraction
  • Disabling AV/EDR via bcdedit tampering and bring-your-own-vulnerable-driver techniques

Current Campaign Analysis

Sectors being targeted: The three new listings cover Manufacturing (Wesmar), Professional Services (a law firm — Krycler, Ervin, Taubman & Kaminsky), and Other (DPL Group). This is consistent with AKIRA's historical victimology: mid-market organizations with operationally sensitive downtime (manufacturing) and organizations holding high-value confidential client data (legal services). Law firms remain a premium target for extortion because privileged client communications maximize pressure.

Geographic concentration: The only listing with a disclosed country is US-based. This aligns with AKIRA's long-standing US-centric targeting, which has historically represented the majority of its claimed victims.

Victim profile: Based on the sectors listed, the alleged targets fit AKIRA's typical profile: small-to-midsize enterprises (roughly 50–500 employees, estimated $10M–$250M annual revenue) — organizations large enough to pay meaningful ransoms but frequently lacking 24/7 SOC coverage, MFA-complete remote access, and immutable backups.

Posting frequency / escalation: Three listings published on a single day (2026-10-01) against the backdrop of 3 postings in the last 100 suggests a batch-publication pattern — affiliates often queue multiple victim disclosures simultaneously when negotiations stall in parallel. Watch for follow-on listings in the next 7–14 days, which would indicate an active affiliate wave rather than isolated claims.

CVE linkage (hypothesis only): We have no evidence tying any specific CVE to any named organization above. However, AKIRA is known to favor edge-device and remote-access exploitation, and several vulnerabilities currently on the CISA KEV with confirmed ransomware use intersect with that tradecraft:

  • CVE-2026-50751 — Check Point Security Gateway Improper Authentication (IKEv1): Directly relevant to AKIRA's VPN-first access pattern. Organizations running Check Point gateways should treat this as an emergency patch item.
  • CVE-2026-20316 — Cisco Secure FMC hard-coded password: Cisco edge/management infrastructure is a recurring AKIRA entry point.
  • CVE-2026-59310 — VMware vCenter path traversal: Relevant to AKIRA's virtualization-layer targeting; their ESXi encryptor makes hypervisor compromise a force multiplier.
  • CVE-2026-63077 — JetBrains TeamCity deserialization: Build-server compromise enables supply-chain-style lateral movement into production environments.
  • CVE-2026-48027 — Nx Console embedded malicious code: Developer-toolchain supply chain exposure relevant to professional services firms with in-house development.

Treat these as sector-level exposure hypotheses, not attribution: patch by KEV priority regardless of whether you match this campaign's victim profile.

Detection Engineering

The following Sigma rules target AKIRA's documented TTPs: VPN/RDP initial access anomalies, pre-encryption shadow copy deletion, and Rclone-based exfiltration staging.

YAML
---
title: AKIRA - Volume Shadow Copy Deletion Pre-Ransomware
id: 8f3a1c2e-akira-4a01-9c11-20261002vss
description: Detects deletion of Volume Shadow Copies via vssadmin, wmic, or PowerShell — a near-universal AKIRA pre-encryption behavior intended to block recovery.
status: production
author: Security Arsenal Threat Intelligence
logsource:
  category: process_creation
  product: windows
level: high
tags:
  - attack.impact
  - attack.t1490
detection:
  selection_vssadmin:
    Image|endswith: '\vssadmin.exe'
    CommandLine|contains|all:
      - 'delete'
      - 'shadows'
  selection_wmic:
    Image|endswith: '\wmic.exe'
    CommandLine|contains:
      - 'shadowcopy delete'
      - 'shadowcopy'
  selection_ps:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
    CommandLine|contains:
      - 'Win32_ShadowCopy'
      - 'Remove-CimInstance'
  condition: selection_vssadmin or selection_wmic or selection_ps
falsepositives:
  - Legitimate backup maintenance scripts (rare — baseline and exclude known admin tooling)
date: 2026/10/02
---
title: AKIRA - Rclone or Cloud Exfiltration Tool Execution with Exfil Flags
id: 9d4b2f1a-akira-4b02-8d22-20261002exf
description: Detects execution of Rclone or common exfiltration tooling with flags consistent with AKIRA data staging (copy/move to remote, multi-threaded transfers). AKIRA affiliates routinely stage exfil before encryption.
status: production
author: Security Arsenal Threat Intelligence
logsource:
  category: process_creation
  product: windows
level: high
tags:
  - attack.exfiltration
  - attack.t1567.002
  - attack.t1048
detection:
  selection_img:
    Image|endswith:
      - '\rclone.exe'
      - '\filezilla.exe'
      - '\winscp.exe'
  selection_flags:
    CommandLine|contains:
      - ' copy '
      - ' move '
      - ' sync '
      - '--transfers'
      - '--multi-thread-streams'
      - 'sftp'
      - ':remote'
  condition: selection_img and selection_flags
falsepositives:
  - IT-managed cloud backup jobs using rclone (whitelist known scheduled tasks and service accounts)
date: 2026/10/02
---
title: AKIRA - Suspicious Remote Access Tool Install or RDP Brute Force Precursor
id: 7e2c9d3b-akira-4c03-7e33-20261002rat
description: Detects installation/execution of AnyDesk or RustDesk (AKIRA persistence tooling) and bursts of failed RDP logons consistent with brute force initial access.
status: production
author: Security Arsenal Threat Intelligence
logsource:
  product: windows
  service: security
level: medium
tags:
  - attack.persistence
  - attack.t1133
  - attack.t1110.001
  - attack.command_and_control
  - attack.t1219
detection:
  selection_logon_fail:
    EventID: 4625
    LogonType:
      - 3
      - 10
  selection_rdp_bruteforce:
    EventID: 4625
    LogonType: 10
    IpAddress|contains: '.'
  condition: selection_rdp_bruteforce
falsepositives:
  - Legitimate user password failures — tune with threshold aggregation (alert on >10 failures per source IP per 10 minutes)
date: 2026/10/02

The following KQL hunts AKIRA's lateral movement and pre-ransomware staging chain in Microsoft Sentinel: LSASS access, PsExec/WMI remote execution, and suspicious service creation in a joined window.

KQL — Microsoft Sentinel / Defender
// AKIRA pre-ransomware staging hunt: LSASS access + remote exec + new services (7d window)
let Window = 7d;
let LsassAccess =
    SecurityEvent
    | where TimeGenerated > ago(Window)
    | where EventID == 4656 or EventID == 4663
    | where ObjectName endswith "lsass.exe"
    | where ProcessName !endswith "MsMpEng.exe" and ProcessName !endswith "wininit.exe"
    | summarize LSASSAccessCount = count(), AccessingProcesses = make_set(ProcessName) by SubjectAccountName, Computer, bin(TimeGenerated, 1h);
let RemoteExec =
    union (
        DeviceProcessEvents
        | where TimeGenerated > ago(Window)
        | where FileName in~ ("psexec.exe", "psexesvc.exe", "wmic.exe")
        | project TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingProcessAccountName
    ), (
        SecurityEvent
        | where TimeGenerated > ago(Window)
        | where EventID == 7045  // new service installed
        | where ServiceName !in~ ("Sense", "WinDefend")
        | project TimeGenerated, Computer, ServiceName, ServiceFileName, AccountName
    );
let ShadowDelete =
    DeviceProcessEvents
    | where TimeGenerated > ago(Window)
    | where ProcessCommandLine has_any ("delete shadows", "shadowcopy delete", "vssadmin delete", "bcdedit", "recoveryenabled no")
    | project TimeGenerated, DeviceName, ProcessCommandLine, InitiatingProcessAccountName;
ShadowDelete
| join kind=leftouter (RemoteExec) on $left.DeviceName == $right.DeviceName
| join kind=leftouter (LsassAccess) on $left.DeviceName == $right.Computer
| extend RiskScore = (iff(isnotempty(ProcessCommandLine1), 40, 0)) + (iff(isnotempty(LSASSAccessCount), 40, 0)) + 20
| where RiskScore >= 40
| order by RiskScore desc, TimeGenerated desc
| project TimeGenerated, DeviceName, ShadowDeleteCmd = ProcessCommandLine, RemoteExecEvidence = ProcessCommandLine1, LSASSAccessCount, RiskScore

The following PowerShell script gives first responders a rapid triage snapshot: recently created scheduled tasks, shadow copy status, exposed RDP configuration, and new local administrators — all AKIRA-relevant persistence and staging artifacts.

PowerShell
# Security Arsenal - AKIRA Rapid Triage Script (run as Administrator)
# Checks: scheduled tasks (7d), shadow copies, RDP exposure, new local admins
Write-Host "=== AKIRA Rapid Triage - $(Get-Date) ===" -ForegroundColor Cyan

Write-Host "`n[1] Scheduled Tasks created/modified in last 7 days:" -ForegroundColor Yellow
Get-ScheduledTask | Where-Object {
    ($_.Date -and ([datetime]$_.Date) -gt (Get-Date).AddDays(-7))
} | Select-Object TaskName, TaskPath, State | Format-Table -AutoSize

Write-Host "`n[2] Volume Shadow Copies (AKIRA deletes these pre-encryption):" -ForegroundColor Yellow
$shadows = Get-WmiObject Win32_ShadowCopy -ErrorAction SilentlyContinue
if ($shadows) { $shadows | Select-Object DeviceObject, InstallDate | Format-Table -AutoSize }
else { Write-Host "  WARNING: No shadow copies found - investigate vssadmin deletion!" -ForegroundColor Red }

Write-Host "`n[3] RDP Configuration & Exposure:" -ForegroundColor Yellow
$rdp = Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections
Write-Host "  RDP Enabled: $(if($rdp.fDenyTSConnections -eq 0){'YES - verify MFA/VPN gating'}else{'No'})"
$nla = Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -ErrorAction SilentlyContinue
Write-Host "  NLA Required: $(if($nla.UserAuthentication -eq 1){'Yes'}else{'NO - enable immediately'})"

Write-Host "`n[4] Local Administrators (look for unexpected additions):" -ForegroundColor Yellow
Get-LocalGroupMember -Group "Administrators" -ErrorAction SilentlyContinue | Select-Object Name, ObjectClass | Format-Table -AutoSize

Write-Host "`n[5] Recent suspicious service installs (Event 7045, 7d):" -ForegroundColor Yellow
Get-WinEvent -FilterHashtable @{LogName='System'; Id=7045; StartTime=(Get-Date).AddDays(-7)} -ErrorAction SilentlyContinue |
    Select-Object TimeCreated, @{N='Service';E={$_.Properties[0].Value}}, @{N='Binary';E={$_.Properties[1].Value}} | Format-Table -AutoSize

Write-Host "`n=== Triage complete. Escalate any red flags to IR immediately. ===" -ForegroundColor Cyan

Incident Response Priorities

T-minus detection checklist (pre-encryption indicators):

  • Shadow copy deletion events (vssadmin, wmic, bcdedit /set {default} recoveryenabled no)
  • New or renamed remote access tools (AnyDesk, RustDesk, SplashTop) on servers
  • Rclone/FileZilla/WinSCP execution, especially with archive staging in unusual directories (C:\ProgramData, C:\Users\Public)
  • LSASS memory access by non-system processes
  • Mass file renames or encryption extension artifacts in honeypot/canary shares
  • New local/domain admin accounts; unexpected Group Policy changes pushing disable-AV scripts
  • Large outbound transfers (>1 GB) to consumer cloud storage or unknown IPs in 24h windows
  • VPN logons from impossible-travel geographies or known VPN-exit/Tor infrastructure

Assets AKIRA historically prioritizes for exfiltration:

  • HR and payroll records (PII for double-extortion leverage)
  • Financial statements, banking and tax documents
  • Legal documents and privileged client communications (critical for the professional services listing pattern above)
  • Manufacturing IP: CAD files, schematics, process documentation, ERP exports
  • Backup catalogs and domain controller data (to maximize destruction before encryption)

Containment actions, ordered by urgency:

  1. Isolate affected VLANs/hosts at the switch level — do not power off (preserve memory artifacts)
  2. Disable VPN access and force credential reset for all accounts active in the suspect window — AKIRA's primary re-entry path is valid credentials
  3. Block identified exfil destinations at the egress proxy/firewall; sinkhole actor infrastructure
  4. Suspend inter-domain trusts and disable compromised service accounts
  5. Snapshot and image domain controllers and file servers before remediation
  6. Engage IR retainer and notify legal counsel/cyber insurance before any communication with the actor
  7. Verify backup integrity from an isolated console — assume backup infrastructure was reconnoitered

Hardening Recommendations

Immediate (24 hours):

  • Enforce MFA on all VPN concentrators (Cisco ASA/AnyConnect, SonicWall, Check Point) — this single control breaks AKIRA's dominant access vector
  • Patch or mitigate CVE-2026-50751 (Check Point IKEv1) and CVE-2026-20316 (Cisco FMC) on internet-facing appliances; if patching is deferred, restrict management interfaces to allow-listed admin IPs
  • Disable or restrict RDP to the internet entirely; require NLA and VPN+RD Gateway
  • Block execution of rclone.exe, AnyDesk, RustDesk via AppLocker/WDAC unless explicitly approved
  • Deploy the Sigma rules above and alert on any shadow copy deletion attempt
  • Audit local admin groups and remove standing admin rights

Short-term (2 weeks):

  • Implement egress filtering with alerting on transfers to consumer cloud storage and newly seen destinations
  • Deploy canary files and decoy shares to trigger pre-encryption alerts
  • Enforce LSA Protection (RunAsPPL) and Credential Guard to blunt LSASS dumping
  • Establish immutable, offline, or air-gapped backups with tested restoration runbooks; separate backup credentials from domain credentials
  • Segment OT/manufacturing networks from IT — for manufacturers matching this campaign's profile, flat networks are what convert an IT intrusion into production downtime
  • Patch CVE-2026-59310 (vCenter) and audit ESXi host access — AKIRA's Linux encryptor targets virtualization layers to maximize blast radius
  • Review CVE-2026-63077 (TeamCity) and CVE-2026-48027 (Nx Console) exposure in developer environments

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.