Akira Ransomware: What It Targets and What's Recoverable
Akira emerged in March 2023, with suspected ties to former Conti affiliates. Its most common entry point is brute-forcing Cisco VPN devices that rely on single-factor authentication, alongside known VPN and firewall vulnerabilities (including CVE-2019-6693 and CVE-2022-40684).
Two distinct variants
The original Akira, written in C++, appends a .akira extension and drops an akira_readme.txt ransom note; it was built on Conti V2 source code, and a free decryptor for this early variant was released by Avast in June 2023. A rewrite in Rust followed within months, distributed as megazord.exe and switching to a .powerranges file extension — a different encryption implementation that the earlier decryptor does not address.
What this means for recovery
Like most modern ransomware, Akira isn't limited to end-user files — servers, VMs and any reachable network storage are in scope. Whether a given incident leaves recoverable remnants depends heavily on which variant was used, how much was encrypted before containment, and whether large files (databases, virtual disks) were fully or only partially encrypted. That's precisely what a technical assessment establishes before anything else — check which extension your files carry (.akira vs .powerranges) and isolate affected systems rather than rebooting or restoring in place.
Dealing with something like this now?
Contact AS for an initial assessment of your recovery situation.