Akira Ransomware Operational Tempo Increase

This was initially a gut feeling, but report frequency as relayed here confirms: Akira has been increasing their optempo. Presumably this is downstream of the Sonicwall breach, and a glut of 0-days.

Akira prefers 0-days as their entry vector.

They tend to work in waves but also this might have some clues in case anyone missed it: https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-109a

This is the part I found most interesting:

In a June 2025 incident, Akira threat actors encrypted Nutanix AHV VM disk files for the first time

1 Like

I don’t think the increase is just Nutanix, but definitely a new capability. And that advisory was updated a couple days ago to confirm exploitation.

No, I don’t think Nutanix is the reason either, just the part I found most interesting in the update.