Akira is a ransomware operation that has remained top-tier into 2026 by relentlessly exploiting edge VPN devices, above all SonicWall SSL-VPNs through CVE-2024-40766. Active since March 2023, Akira runs a smash-and-grab model, often deploying ransomware within an hour of gaining access, and uses bring-your-own-vulnerable-driver techniques to disable endpoint defenses. It encrypts both Windows and Linux or ESXi systems and practices double extortion. In June 2026 it ranked among the most active groups tracked, sustaining a campaign that began in mid-2025 and never let up.
Who is Akira?
Akira is a double-extortion ransomware group first seen in March 2023, known for a retro terminal-style leak site and a high operational tempo. It steals data before encrypting and pressures victims with the threat of publication. The group has been the subject of CISA advisories and sustained vendor tracking. It is one of the operations that anchors the 2026 top tier alongside Qilin and The Gentlemen. Track its listings on the Ransomtracker feed.
How does Akira get in?
Akira’s signature is edge-device exploitation, and its most persistent campaign targets SonicWall SSL-VPNs via CVE-2024-40766. The campaign began in mid-2025 and continued into 2026, with researchers noting cases that bypassed multi-factor authentication and led to ransomware deployment within roughly an hour of access. That speed is the point: by compressing the time from foothold to encryption, Akira gives defenders almost no window to detect and respond before the damage is done.
What does Akira do once inside?
After breaching a VPN, Akira harvests credentials, scans the network, and uses tools such as Impacket for SMB operations to move laterally. It deploys bring-your-own-vulnerable-driver techniques to disable endpoint detection, then encrypts. On virtualized estates it targets Linux and ESXi builds to maximize impact. The group’s discipline in chaining edge access to rapid encryption, with an EDR-kill step in between, is what keeps it effective against organizations that patched slowly or exposed VPNs without strong authentication.
How to defend against Akira
Patch SonicWall and other SSL-VPN appliances immediately and treat CVE-2024-40766 as a live threat until every device is confirmed fixed. Enforce phishing-resistant multi-factor authentication on remote access, because Akira has bypassed weaker second factors. Enable Microsoft’s vulnerable-driver blocklist to blunt the BYOVD step, and alert on a new kernel driver loading just before security services stop. Given the sub-hour timeline, offline backups and a rehearsed response plan matter as much as detection, since the encryption may land before an analyst can intervene. See our Active Directory hardening guidance for limiting lateral movement.
Frequently asked questions
What is Akira ransomware?
Akira is a double-extortion ransomware group active since March 2023, known for exploiting edge VPN devices and deploying ransomware very quickly after gaining access.
How does Akira exploit SonicWall devices?
Akira targets SonicWall SSL-VPNs through CVE-2024-40766, a campaign that began in mid-2025 and continued into 2026, in some cases bypassing multi-factor authentication.
How fast does Akira deploy ransomware?
Researchers have observed Akira deploying ransomware within roughly an hour of initial access, a smash-and-grab tempo that leaves defenders little time to respond.
Does Akira use BYOVD?
Yes. Akira uses bring-your-own-vulnerable-driver techniques to disable endpoint detection before encrypting, a common step among 2026’s top ransomware operations.
What systems does Akira encrypt?
Akira encrypts both Windows and Linux or ESXi systems, targeting virtualization infrastructure to maximize the impact of a single intrusion.
