Security1 publisher3 min readPublished
Akira advisory update: $244m taken, one SonicWall CVE, three controls to audit now
Nine agencies across four countries refreshed the #StopRansomware Akira advisory on Nov. 13 with indicators current to November 2025 and a three-item action list.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- The advisory was originally published April 18, 2024, and was updated Nov. 13, 2025 with information on new Akira ransomware activity.
- The authoring organizations of the Nov. 13, 2025 update are the US FBI, CISA, Department of Defense Cyber Crime Center (DC3) and Department of Health and Human Services; Europol's European Cybercrime Centre (EC3); France's Office Anti-Cybercriminalite (OFAC), the French Cybercrime Central Office; Germany's Generalstaatsanwaltschaft Karlsruhe - Cybercrime-Zentrum Baden-Wuerttemberg and Landeskriminalamt Baden-Wuerttemberg; and the Netherlands' National Cyber Security Centre (NCSC-NL).
- The joint advisory disseminates known Akira ransomware IOCs and TTPs identified through FBI investigations and trusted third-party reporting as recently as November 2025.
- The Nov. 13, 2025 update states that the new Akira ransomware activity presents an imminent threat to critical infrastructure.
- The advisory was originally published April 18, 2024.
Compiled by The WatchSomething wrong?How this is made
Why it matters
The FBI, CISA, the Defense Department's Cyber Crime Center and HHS, joined by Europol's European Cybercrime Centre, France's Office Anti-Cybercriminalite (abbreviated in the advisory as OFAC), German prosecutors and state police in Karlsruhe and Baden-Wurttemberg, and the Netherlands' NCSC-NL, republished the #StopRansomware advisory on Akira ransomware on Nov. 13, 2025 [1][2]. The update carries indicators of compromise and TTPs drawn from FBI investigations and trusted third-party reporting as recently as November 2025, and states that the new activity presents an imminent threat to critical infrastructure [3][4].
That is a government-attested detection package with nine agency names on it, which changes the internal argument about priority [2]. The advisory was first published April 18, 2024, so roughly nineteen months of accumulated activity sits in the update [5][6].
The financial line is the one to quote upward. As of late September 2025, Akira had claimed approximately $244.17 million in ransomware proceeds, according to the authoring organizations [7]. Activity dates to March 2023 across North America, Europe and Australia [8], which works out to an average of about $7.9 million a month over 31 months [9].
The target profile is not the Fortune 100. Akira actors primarily hit small and medium businesses, with a noted preference for educational institutions and the Critical Manufacturing, IT, Healthcare and Public Health, Financial Services, and Food and Agriculture sectors, though larger organisations have been affected too [10]. The group is tracked elsewhere as Storm-1567, Howling Scorpius, Punk Spider and Gold Sahara, and may have connections to the defunct Conti group [11].
Two technical details deserve attention beyond the IOC lists. First, initial access: the advisory says Akira actors likely abused CVE-2024-40766, a SonicWall improper access control flaw, to get in [12]. That gives the abstract instruction to prioritise remediating known exploited vulnerabilities [13] a specific name and a specific appliance class to go look at. Second, the virtualisation layer: after an initial Windows focus, a Linux variant aimed at VMware ESXi virtual machines appeared in April 2023 [14], and per trusted third-party reporting, payloads were deployed against Nutanix Acropolis Hypervisor systems in a June 2025 incident [15]. Backup restoration tests that only prove file-level recovery on Windows endpoints do not answer that threat.
The other two actions in the advisory's own summary are enforcing phishing-resistant MFA [16] and keeping regular backups of critical data stored offline with the restoration process regularly tested [17]. Neither is new advice. The difference is that there is now a dated, multi-government document naming the variant, the encryptors (C++ with a .akira extension originally, and since August 2023 the Rust-based Megazord writing .powerranges, both still in rotation alongside Akira_v2) [18][19], and a mapping to MITRE ATT&CK for Enterprise version 18 [20].
Two files were posted for download, one of November 2025 indicators and one of historic indicators [21]. Loading only the new file is the predictable half-measure.
Watch whether the SonicWall path keeps producing victims now that it has been named in a joint advisory, and whether the June 2025 Nutanix incident was an outlier or the start of a second hypervisor line after ESXi [12][15][14]. The $244.17 million figure is also a benchmark: the next revision's number will say whether any of this landed [7].