TF-MAL-elf.akira
📛 Threat Title
Malware family: Akira
Description
ThreatFox malware family `elf.akira`. Printable name: Akira. Aliases: REDBIKE.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.akira
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.akira
IOC database
- Type
- domain
- Value
elf.akira- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.akira
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.akira
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybelangel.com
Akira is a ransomware-as-a-service (RaaS) gang that emerged in March 2023. Anyone can use Akira's malware to steal and encrypt sensitive data, such as by phishing, only returning it after receiving a ransom payment, with sums ranging from $200,000 to millions.
-
web:cybernews.com
The Akira ransomware group has updated its arsenal, introduced the new Akira_v2 variant, and has extorted nearly $244.17 million by late September 2025.
-
web:purple-ops.io
PurpleOps and Mitigation of Akira Ransomware PurpleOps provides a suite of cybersecurity services designed to help organizations mitigate the risks associated with ransomware attacks, including those perpetrated by the Akira group.
-
web:www.aha.org
A joint advisory issued yesterday by U.S. and international agencies provides updated guidance to defend against the Akira ransomware group, which has previously conducted cyberattacks against hospitals and health care organizations.
-
web:www.bleepingcomputer.com
The Akira ransomware gang is actively exploiting CVE-2024-40766, a year-old critical-severity access control vulnerability, to gain unauthorized access to SonicWall devices.
-
web:www.cisa.gov
Akira ransomware threat actors are associated with other groups known as Storm-1567, Howling Scorpius, Punk Spider, and Gold Sahara, and may have connections to the defunct Conti ransomware group. Akira threat actors primarily target small- and medium-sized businesses, but have also impacted larger organizations across various sectors.
-
web:www.fbi.gov
Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Akira Ransomware Activity Prioritize remediating known exploited vulnerabilities.
-
web:www.ic3.gov
Actions to take today to mitigate cyber threats from Akira ransomware: Prioritize remediating known exploited vulnerabilities.
-
web:www.picussecurity.com
Learn how Akira ransomware operates in 2025 with updated CISA findings. Explore its latest TTPs, initial access methods, and actionable defense strategies.
-
web:www.sentinelone.com
Akira Ransomware is known for its retro aesthetic that's applied to its DLS. Learn about its multi-extortion tactics, negotiation processes, and mitigation techniques.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.