Akira group rapid double-extortion ransomware activity
Malware Activity
Summary
Hide ▲
Show ▼
Akira ransomware activity now includes AdaptixC2 abuse in active intrusions, adding another tool to a campaign already known for rapid double-extortion. A Silent Push analysis ties the deployment to CountLoader and reports a DFIR case involving an Akira affiliate, while researchers say some Akira attacks can finish in under one hour and often start through internet-facing VPN appliances or backup solutions lacking MFA. The group exfiltrates data before encryption, uses FileZilla, WinRAR, WinSCP and RClone, and the US government says Akira has generated as much as $244m since March 2023.
Related Happenings
Foxconn claimed data leak by Nitrogen ransomware group
Data Leak
H score72
First: 13.05.2026 20:13
Last: 13.05.2026 20:13
Sources 1
About this happening:
The Nitrogen ransomware group claimed a Foxconn data leak involving 8TB and more than 11 million files, raising the risk that confidential manufacturing material t...
Foxconn claimed data leak by Nitrogen ransomware group
Data LeakAbout this happening: The Nitrogen ransomware group claimed a Foxconn data leak involving 8TB and more than 11 million files, raising the risk that confidential manufacturing material t...
PCPJack TeamPCP-targeting cloud credential theft campaign
Campaign
H score37
First: 08.05.2026 12:00
Last: 08.05.2026 12:00
Sources 1
About this happening:
A new PCPJack campaign is targeting TeamPCP victims by worming across exposed cloud infrastructure, creating a fresh risk of credential theft and unauthorized reuse of...
PCPJack TeamPCP-targeting cloud credential theft campaign
CampaignAbout this happening: A new PCPJack campaign is targeting TeamPCP victims by worming across exposed cloud infrastructure, creating a fresh risk of credential theft and unauthorized reuse of...
MuddyWater Microsoft Teams social-engineering campaign with Chaos ransomware decoy
Campaign
H score37
First: 06.05.2026 16:02
Last: 06.05.2026 16:02
Sources 1
About this happening:
The MuddyWater campaign used Microsoft Teams social engineering and a Chaos ransomware decoy to gain access, steal credentials, and establish persistence. The operatio...
MuddyWater Microsoft Teams social-engineering campaign with Chaos ransomware decoy
CampaignAbout this happening: The MuddyWater campaign used Microsoft Teams social engineering and a Chaos ransomware decoy to gain access, steal credentials, and establish persistence. The operatio...
Vect 2.0 ransomware wiper-flaw activity
Malware Activity
H score31
First: 29.04.2026 18:23
Last: 29.04.2026 18:23
Sources 1
About this happening:
The Vect 2.0 ransomware variant now permanently destroys large files instead of encrypting them, which can leave defenders without a recoverable copy. The flaw affects ver...
Vect 2.0 ransomware wiper-flaw activity
Malware ActivityAbout this happening: The Vect 2.0 ransomware variant now permanently destroys large files instead of encrypting them, which can leave defenders without a recoverable copy. The flaw affects ver...
Vect ransomware flawed ChaCha20 implementation destroys large files
Technical Analysis
H score4
First: 29.04.2026 13:45
Last: 29.04.2026 13:45
Sources 1
About this happening:
Vect 2.0 ransomware was shown to use raw ChaCha20-IETF (RFC 8439) without authentication, causing files above 128 KB to be permanently destroyed across Windows, Linu...
Vect ransomware flawed ChaCha20 implementation destroys large files
Technical AnalysisAbout this happening: Vect 2.0 ransomware was shown to use raw ChaCha20-IETF (RFC 8439) without authentication, causing files above 128 KB to be permanently destroyed across Windows, Linu...
Timeline
-
02.04.2026 16:00 3 articles · 3mo ago
Akira rapid double-extortion tradecraft report
Technical Analysis UpdateResearchers assess that Akira can complete a full ransomware lifecycle in under four hours and, in some cases, in less than one hour, often after initial access through internet-facing VPN appliances or backup solutions lacking MFA. The group exfiltrates data before encryption in a double-extortion workflow, disables security software to evade detection, and uses FileZilla, WinRAR, WinSCP, and RClone for staging and encryption.
Show sources
- Researchers Observe Sub-One-Hour Ransomware Attacks — www.infosecurity-magazine.com — 02.04.2026 16:00
- Researchers Observe Sub-One-Hour Ransomware Attacks — www.infosecurity-magazine.com — 02.04.2026 16:00
- Threat Actors Utilize AdaptixC2 for Malicious Payload Delivery — www.infosecurity-magazine.com — 30.10.2025 18:00