Threat Actors to Watch: Akira and Storm-1175
From a ransomware-as-a-service group that can move from initial access to full encryption in under four hours, to a China-linked affiliate that has quietly pivoted to its own encryptor, these two threat actors show how mature the ransomware ecosystem has become. CYJAX breaks down what each group does, why they matter, and what security teams should know.

From a ransomware-as-a-service group that can move from initial access to full encryption in under four hours, to a China-linked affiliate that has quietly pivoted to its own encryptor, these two threat actors show how mature the ransomware ecosystem has become. CYJAX breaks down what each group does, why they matter, and what security teams should know.
Key takeaways
- Akira has listed more than 1,500 victims on its leak site as of July 2026 and has collected approximately $244.17 million in ransom proceeds since 2023, making it one of the most profitable ransomware operations of 2025.
- Akira has extended its destructive reach from Windows and VMware ESXi into Hyper-V and, as of June 2025, Nutanix AHV, and has been observed using unrotated credentials from recent mergers and acquisitions to reach larger downstream targets.
- Storm-1175, a China-linked Medusa ransomware affiliate, has begun distributing its own encryptor named StormEncryptor as of August 2026, its first observed activity since April 2026.
- Both groups favour legitimate remote monitoring and management tools over custom malware, which helps their activity blend into normal administrator behaviour and complicates detection.
- Speed is a defining trait for both actors: Akira has completed some attacks in under an hour, while Storm-1175 has moved from compromise to encryption within 24 hours in several cases.
Understanding Threat Actor Intelligence
Ransomware groups increasingly resemble businesses, running affiliate programmes, maintaining public leak sites, and rotating tooling as defences catch up. That maturity cuts both ways for defenders: it makes attacker behaviour more predictable in some respects, but it also means groups can absorb setbacks such as arrests or infrastructure takedowns and continue operating with minimal disruption.
The volume of alerts and indicators security teams are asked to triage keeps growing, which makes it harder to separate a credible, active threat from background noise. Knowing which groups are currently active, how they gain access, and where they tend to go next is what turns that triage process into something actionable.
Below, CYJAX profiles two active ransomware threats that organisations across multiple sectors and regions should be monitoring closely right now.
1. Akira
Type: Ransomware-as-a-Service | Motivation: Financial | Threat Level: Critical
Who The Group Is
Akira, also tracked as Storm-1567, HowlingScorpius, PunkSpider, and GoldSahara, is a financially motivated ransomware-as-a-service group that has been active since at least March 2023. It predominantly targets small and medium-sized enterprises, though it has also compromised large organisations, across manufacturing, professional services, technology, education, healthcare, financial services, and construction. Victims are concentrated in the United States, Canada, Australia, and Europe. The group is linked to the defunct Conti ransomware operation through shared code and operational overlap, which researchers attribute to former Conti members, reused source code, or both.
What It Does
Akira gains initial access primarily by exploiting vulnerabilities in edge devices and backup software, including SonicWall SonicOS, Cisco ASA and FTD, and Veeam Backup and Replication, and by logging in with compromised VPN credentials. Once inside, it relies heavily on legitimate remote access and file transfer tools rather than extensive custom tooling, which keeps its footprint close to normal administrator activity. The group exfiltrates data using tools such as Rclone before encrypting systems with a hybrid ChaCha20 and RSA scheme, supporting full or partial encryption depending on file type and size. Complete attack chains, from initial access to encryption, have been documented in under four hours, and in some cases under one hour. In June 2025, Akira encrypted Nutanix AHV virtual machine disk files for the first time, having gained access through a SonicWall SSL VPN vulnerability, extending its reach beyond VMware ESXi and Hyper-V.
Why It Matters
Akira's attack tempo has remained high through 2026, with its leak site listing 84 new victims in March alone, and by early 2026 it ranked second globally by claimed victim volume. Its exploitation of technology inherited through mergers and acquisitions, using overlooked devices and unrotated credentials, has allowed it to reach larger organisations that would otherwise be harder to compromise directly. In one October 2025 campaign, the group reached a domain controller in an average of just over nine hours through this route. For security teams, the priority exposure points are internet-facing VPN gateways, backup platforms, and hypervisor management interfaces, all of which have repeatedly served as Akira's route into victim networks.
2. Storm-1175
Aliases: — | Type: Ransomware affiliate | Motivation: Financial | Threat Level: Critical
Who The Group Is
Storm-1175 is a China-linked threat group that has been active since at least March 2023, though it was first reported on publicly in October 2025. It is best known as an affiliate of the Medusa ransomware-as-a-service operation, though as of August 2026 it has also been observed distributing a new ransomware strain named StormEncryptor. The group predominantly targets the healthcare, education, finance, and professional services sectors across the UK, US, and Australia. While believed to be China-based due to operational and language markers, there are no indications it is state-sponsored, and it is tracked as a standalone, financially motivated actor.
What It Does
Storm-1175 gains initial access by exploiting vulnerabilities across a wide range of internet-facing products, including Microsoft Exchange, Ivanti, SAP NetWeaver, ConnectWise ScreenConnect, JetBrains TeamCity, CrushFTP, GoAnywhere MFT, SimpleHelp, BeyondTrust, SmarterMail, and PaperCut, in some cases chaining flaws for post-compromise activity. After gaining access, it abuses remote monitoring and management tools such as AnyDesk, SimpleHelp, and MeshAgent for persistence and command and control, and uses tools including NetScan, Advanced IP Scanner, and Mimikatz for discovery and credential access. The group has previously deployed the Medusa ransomware as an affiliate. As of August 2026, it has also been linked to StormEncryptor, a C++ encryptor that appends the .encrypted extension and drops a ransom note named "!!!README_FIRST!!!.txt." It is not yet clear whether StormEncryptor is a strain Storm-1175 developed itself or whether the group is affiliated with a separate, new RaaS offering.
Why It Matters
Storm-1175 moves quickly once inside a network, with researchers documenting compromise-to-encryption timelines as short as 24 hours, and its heavy reliance on legitimate RMM tools allows it to maintain persistence for several days without detection. Its pivot to StormEncryptor in August 2026, its first observed activity since April, suggests the group is either diversifying beyond its Medusa affiliation or testing a new RaaS relationship, either of which points to continued adaptation rather than a group winding down. For organisations in healthcare, education, finance, and professional services, particularly those running any of the frequently exploited products above, patching cadence and RMM tool visibility are the most consequential controls.
Monitoring groups like these requires more than threat feeds and alerts. It requires knowing which group is active, its targets, and what your organisation looks like from its perspective. Book a demo with CYJAX to see how our analyst-led intelligence platform helps your team move from reactive to ready.
Get Started with CYJAX CTI
Empower Your Team. Strengthen Your Defences.CYJAX gives you the intelligence advantage: clear, validated insights that let your team act fast without being buried in noise.


