AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
Akira
Aliases: GOLD SAHARA, PUNK SPIDER
Akira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates multiple overlaps with and similarities to Conti malware.
Open interactive actor investigation
ATT&CK techniques
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Blue Team & Defensive Security · explicit-idModule 5 — Threat hunting
Blue Team & Defensive Security · explicit-nameWindows endpoint and identity forensics
Digital Forensics & Incident Response (DFIR) · explicit-nameModule 7 — Endpoint defense and EDR
Blue Team & Defensive Security · topic-matchModule 13 — AI-assisted defense, RAG, agents, and MCP
Blue Team & Defensive Security · topic-matchModule 9 — AI-assisted offensive security and MCP
Red Team & Offensive Security · topic-matchModule 2 — The Intelligence Cycle Intelligence Types
Cyber Threat Intelligence (CTI) · topic-matchEmbedded, firmware, hardware, and update-chain research
Vulnerability Research & Exploit Development · topic-matchDisassembly, decompilation, and code-led analysis
Malware Analysis & Reverse Engineering · topic-matchRequirements, ownership, inventory, and data flow
Secure Code & Application Security · topic-matchModule 9 — Identity defense and ITDR
Blue Team & Defensive Security · topic-matchModule 12 — Incident response, DFIR, crisis coordination, and recovery
Blue Team & Defensive Security · topic-match