s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.akira

📛 Threat Title

Malware family: Akira

Category: Akira First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.akira`. Printable name: Akira. Aliases: REDBIKE.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.akira VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.akira

IOC database

Type
domain
Value
elf.akira
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.akira

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.akira

References (1)

Remediations (10)

  • web:cybelangel.com

    Akira is a ransomware-as-a-service (RaaS) gang that emerged in March 2023. Anyone can use Akira's malware to steal and encrypt sensitive data, such as by phishing, only returning it after receiving a ransom payment, with sums ranging from $200,000 to millions.

  • web:cybernews.com

    The Akira ransomware group has updated its arsenal, introduced the new Akira_v2 variant, and has extorted nearly $244.17 million by late September 2025.

  • web:purple-ops.io

    PurpleOps and Mitigation of Akira Ransomware PurpleOps provides a suite of cybersecurity services designed to help organizations mitigate the risks associated with ransomware attacks, including those perpetrated by the Akira group.

  • web:www.aha.org

    A joint advisory issued yesterday by U.S. and international agencies provides updated guidance to defend against the Akira ransomware group, which has previously conducted cyberattacks against hospitals and health care organizations.

  • web:www.bleepingcomputer.com

    The Akira ransomware gang is actively exploiting CVE-2024-40766, a year-old critical-severity access control vulnerability, to gain unauthorized access to SonicWall devices.

  • web:www.cisa.gov

    Akira ransomware threat actors are associated with other groups known as Storm-1567, Howling Scorpius, Punk Spider, and Gold Sahara, and may have connections to the defunct Conti ransomware group. Akira threat actors primarily target small- and medium-sized businesses, but have also impacted larger organizations across various sectors.

  • web:www.fbi.gov

    Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Akira Ransomware Activity Prioritize remediating known exploited vulnerabilities.

  • web:www.ic3.gov

    Actions to take today to mitigate cyber threats from Akira ransomware: Prioritize remediating known exploited vulnerabilities.

  • web:www.picussecurity.com

    Learn how Akira ransomware operates in 2025 with updated CISA findings. Explore its latest TTPs, initial access methods, and actionable defense strategies.

  • web:www.sentinelone.com

    Akira Ransomware is known for its retro aesthetic that's applied to its DLS. Learn about its multi-extortion tactics, negotiation processes, and mitigation techniques.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.