Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

Akira: the edge-VPN ransomware that never slowed down

Jesse William McGrawBy Jesse William McGrawJuly 16, 2026Updated:July 18, 2026No Comments4 Mins Read69 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Akira: the edge-VPN ransomware that never slowed down, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Akira is a ransomware operation that has remained top-tier into 2026 by relentlessly exploiting edge VPN devices, above all SonicWall SSL-VPNs through CVE-2024-40766. Active since March 2023, Akira runs a smash-and-grab model, often deploying ransomware within an hour of gaining access, and uses bring-your-own-vulnerable-driver techniques to disable endpoint defenses. It encrypts both Windows and Linux or ESXi systems and practices double extortion. In June 2026 it ranked among the most active groups tracked, sustaining a campaign that began in mid-2025 and never let up.

Who is Akira?

Akira is a double-extortion ransomware group first seen in March 2023, known for a retro terminal-style leak site and a high operational tempo. It steals data before encrypting and pressures victims with the threat of publication. The group has been the subject of CISA advisories and sustained vendor tracking. It is one of the operations that anchors the 2026 top tier alongside Qilin and The Gentlemen. Track its listings on the Ransomtracker feed.

How does Akira get in?

Akira’s signature is edge-device exploitation, and its most persistent campaign targets SonicWall SSL-VPNs via CVE-2024-40766. The campaign began in mid-2025 and continued into 2026, with researchers noting cases that bypassed multi-factor authentication and led to ransomware deployment within roughly an hour of access. That speed is the point: by compressing the time from foothold to encryption, Akira gives defenders almost no window to detect and respond before the damage is done.

AKIRA // SMASH-AND-GRAB, UNDER ONE HOUR T+0SonicWall VPNCVE-2024-40766 T+15mrecon +credential theft T+30mBYOVD killsEDR T+45mexfiltratedata ~T+60mencrypt PROFILE Active since: March 2023 | Model: double extortion, data theft + encryption Targets: Windows + Linux/ESXi | Access: SonicWall / edge VPNs, Impacket SMB EDR bypass: bring-your-own-vulnerable-driver (BYOVD) SonicWall campaign began mid-2025, still active into 2026 (CISA advisory issued)

What does Akira do once inside?

After breaching a VPN, Akira harvests credentials, scans the network, and uses tools such as Impacket for SMB operations to move laterally. It deploys bring-your-own-vulnerable-driver techniques to disable endpoint detection, then encrypts. On virtualized estates it targets Linux and ESXi builds to maximize impact. The group’s discipline in chaining edge access to rapid encryption, with an EDR-kill step in between, is what keeps it effective against organizations that patched slowly or exposed VPNs without strong authentication.

How to defend against Akira

Patch SonicWall and other SSL-VPN appliances immediately and treat CVE-2024-40766 as a live threat until every device is confirmed fixed. Enforce phishing-resistant multi-factor authentication on remote access, because Akira has bypassed weaker second factors. Enable Microsoft’s vulnerable-driver blocklist to blunt the BYOVD step, and alert on a new kernel driver loading just before security services stop. Given the sub-hour timeline, offline backups and a rehearsed response plan matter as much as detection, since the encryption may land before an analyst can intervene. See our Active Directory hardening guidance for limiting lateral movement.

Frequently asked questions

What is Akira ransomware?

Akira is a double-extortion ransomware group active since March 2023, known for exploiting edge VPN devices and deploying ransomware very quickly after gaining access.

How does Akira exploit SonicWall devices?

Akira targets SonicWall SSL-VPNs through CVE-2024-40766, a campaign that began in mid-2025 and continued into 2026, in some cases bypassing multi-factor authentication.

How fast does Akira deploy ransomware?

Researchers have observed Akira deploying ransomware within roughly an hour of initial access, a smash-and-grab tempo that leaves defenders little time to respond.

Does Akira use BYOVD?

Yes. Akira uses bring-your-own-vulnerable-driver techniques to disable endpoint detection before encrypting, a common step among 2026’s top ransomware operations.

What systems does Akira encrypt?

Akira encrypts both Windows and Linux or ESXi systems, targeting virtualization infrastructure to maximize the impact of a single intrusion.

Sources and further reading

  • Dark Reading: Akira’s broad SonicWall VPN ransomware campaign
  • Darktrace: Inside Akira’s SonicWall campaign
  • CISA: #StopRansomware Akira advisory
  • Ransomnews threat-group catalogue
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleCoca-Cola’s Fairlife halts US production after ransomware
Next Article macOS.Gaslight: malware that prompt-injects your SOC
Jesse William McGraw

Jesse William McGraw, also known as GhostExodus, is a former insider threat and threat actor. He became the first person in recent U.S. history to be convicted of corrupting industrial control systems. Today he focuses on threat intelligence, OSINT, and public speaking, using his knowledge to bring awareness to the security risks that organisations and individuals face.

Related Posts

Deadlock: ransomware that hides its C2 on the blockchain

July 18, 2026

Clover Health discloses social-engineering breach in 8-K

July 18, 2026

DragonForce: the cartel that absorbed its rivals

July 17, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.