Security1 distinct publisher3 min readUpdated
Nine agencies across four countries refreshed the #StopRansomware Akira advisory on Nov. 13 with indicators current to November 2025 and a three-item action list.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The FBI, CISA, the Defense Department's Cyber Crime Center and HHS, joined by Europol's European Cybercrime Centre, France's Office Anti-Cybercriminalite (abbreviated in the advisory as OFAC), German prosecutors and state police in Karlsruhe and Baden-Wurttemberg, and the Netherlands' NCSC-NL, republished the #StopRansomware advisory on Akira ransomware on Nov. 13, 2025 [1][2]. The update carries indicators of compromise and TTPs drawn from FBI investigations and trusted third-party reporting as recently as November 2025, and states that the new activity presents an imminent threat to critical infrastructure [3][4].
That is a government-attested detection package with nine agency names on it, which changes the internal argument about priority [2]. The advisory was first published April 18, 2024, so roughly nineteen months of accumulated activity sits in the update [5][6].
The financial line is the one to quote upward. As of late September 2025, Akira had claimed approximately $244.17 million in ransomware proceeds, according to the authoring organizations [7]. Activity dates to March 2023 across North America, Europe and Australia [8], which works out to an average of about $7.9 million a month over 31 months [9].
The target profile is not the Fortune 100. Akira actors primarily hit small and medium businesses, with a noted preference for educational institutions and the Critical Manufacturing, IT, Healthcare and Public Health, Financial Services, and Food and Agriculture sectors, though larger organisations have been affected too [10]. The group is tracked elsewhere as Storm-1567, Howling Scorpius, Punk Spider and Gold Sahara, and may have connections to the defunct Conti group [11].
Two technical details deserve attention beyond the IOC lists. First, initial access: the advisory says Akira actors likely abused CVE-2024-40766, a SonicWall improper access control flaw, to get in [12]. That gives the abstract instruction to prioritise remediating known exploited vulnerabilities [13] a specific name and a specific appliance class to go look at. Second, the virtualisation layer: after an initial Windows focus, a Linux variant aimed at VMware ESXi virtual machines appeared in April 2023 [14], and per trusted third-party reporting, payloads were deployed against Nutanix Acropolis Hypervisor systems in a June 2025 incident [15]. Backup restoration tests that only prove file-level recovery on Windows endpoints do not answer that threat.
The other two actions in the advisory's own summary are enforcing phishing-resistant MFA [16] and keeping regular backups of critical data stored offline with the restoration process regularly tested [17]. Neither is new advice. The difference is that there is now a dated, multi-government document naming the variant, the encryptors (C++ with a .akira extension originally, and since August 2023 the Rust-based Megazord writing .powerranges, both still in rotation alongside Akira_v2) [18][19], and a mapping to MITRE ATT&CK for Enterprise version 18 [20].
Two files were posted for download, one of November 2025 indicators and one of historic indicators [21]. Loading only the new file is the predictable half-measure.
Watch whether the SonicWall path keeps producing victims now that it has been named in a joint advisory, and whether the June 2025 Nutanix incident was an outlier or the start of a second hypervisor line after ESXi [12][15][14]. The $244.17 million figure is also a benchmark: the next revision's number will say whether any of this landed [7].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Akira threat actors likely abused CVE-2024-40766, a SonicWall vulnerability classified as CWE-284 improper access control, for initial access.
Among the actions for organizations to take today, the advisory lists prioritizing remediation of known exploited vulnerabilities.
The advisory's actions to take today include enabling and enforcing phishing-resistant multifactor authentication.
The advisory's actions to take today include maintaining regular backups of critical data, storing backups offline, and regularly testing the restoration process.
The advisory was originally published April 18, 2024, and was updated Nov. 13, 2025 with information on new Akira ransomware activity.
The authoring organizations of the Nov. 13, 2025 update are the US FBI, CISA, Department of Defense Cyber Crime Center (DC3) and Department of Health and Human Services; Europol's European Cybercrime Centre (EC3); France's Office Anti-Cybercriminalite (OFAC), the French Cybercrime Central Office; Germany's Generalstaatsanwaltschaft Karlsruhe - Cybercrime-Zentrum Baden-Wuerttemberg and Landeskriminalamt Baden-Wuerttemberg; and the Netherlands' National Cyber Security Centre (NCSC-NL).
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary multi-agency advisory, single publisher, hedged key figures
The sole source is the authoritative primary document itself, co-signed by nine organizations across the US, Europol, France, Germany and the Netherlands, and it ships checkable artifacts: named CVEs with CWE classifications, ATT&CK v18 mappings, and separate current and historic IOC downloads. Evidence quality is held below the top band because the cluster contains no independent corroboration, and the load-bearing quantitative and attribution claims are self-hedged ('likely abused', 'may have connections', 'based on trusted third-party reporting') with no disclosed methodology for the $244.17 million total.
Threat activity well documented; defender uptake unmeasured
Adoption here is read as documented real-world occurrence of the described activity rather than uptake of a product. That side is solid: continuous activity since March 2023 across North America, Europe and Australia, an approximately $244.17 million proceeds total as of late September 2025, hypervisor targeting extended to Nutanix AHV in a June 2025 incident, and exploitation of CVE-2024-40766 for initial access. It is not higher because the advisory gives no victim or incident counts, and supplies nothing at all on whether organizations have implemented the three recommended controls or patched the named CVEs, so mitigation adoption is unmeasured.
Broadly aligned; urgency framing slightly ahead of disclosed method
The document's strongest rhetorical move — new activity presenting an 'imminent threat to critical infrastructure' — is largely backed by dated, specific evidence (November 2025 indicators, a June 2025 hypervisor incident, a named exploited CVE, a quantified proceeds total), and the advisory hedges attribution rather than overstating it. A small positive gap remains because the imminence characterization and the precise $244.17 million figure arrive without counts or methodology, and the cluster has no independent source to test them.
Public-mandate publisher, no commercial stake, mild urgency incentive
Scored so that higher means stronger incentive to shape the narrative. The publisher is a government agency issuing joint defensive guidance with law-enforcement and national CERT co-authors; there is no product to sell, no pricing or licensing interest, and the artifacts are free downloads. Residual incentive is institutional: agencies benefit from defenders acting on their guidance, which favors urgency language such as 'imminent threat', and naming third-party vendor products carries reputational externalities the advisory does not adjudicate.
High source authority, low source diversity
Confidence is high on the operational specifics — action list, ATT&CK v18 mapping, CVE and CWE identifiers, encryptor lineage and IOC packaging — because these come verbatim from the primary co-signed advisory. It is capped by structural single-publisher dependence: one source item, no independent verification of the proceeds estimate, the Conti linkage or the Nutanix AHV incident, and one derived figure (about $7.9 million per month) that is our arithmetic rather than an advisory assertion.
security
Gunra Goes Franchise: Conti's Leaked Code Now Ships With a Builder and an Affiliate Panel2 distinct publishers
security
FBI counts 30-plus ransomware disruptions this year, and the target is the plumbing1 distinct publisher
product
A dozen states, no marquee targets: the water hacks show where the attack surface actually is1 distinct publisher
security
Nitrogen's ESXi encryptor is broken, which means the ransom buys nothing1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 18, 2026