Skip to content
New Ransomware Campaign Mimics Akira Targeting South American Windows Users

New Ransomware Campaign Mimics Akira Targeting South American Windows Users

First seen 2 Apr 2026, 16:32 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 3, 2026 at 16:32 UTC
  • •A new ransomware campaign is targeting Windows users in South America.
  • •The campaign closely mimics the Akira ransomware group's branding and tactics.
  • •No specific CVEs have been disclosed, but the threat is currently active.

A new ransomware campaign has emerged, specifically targeting Windows users in South America. This campaign closely imitates the notorious Akira ransomware group, adopting similar branding, ransom notes, and dark web infrastructure references. ESET has identified that the threat actors are leveraging Akira's reputation to enhance the effectiveness of their attacks. The attack method involves exploiting vulnerabilities in Windows systems, although specific CVEs have not been disclosed. The scope of the impact is currently limited to South America, but the potential for broader implications exists if the campaign spreads. Security professionals are advised to remain vigilant as the situation develops. The current status of the campaign is active, with ongoing investigations into the threat actors' tactics and tools.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 190d ago How this analysis works

Timeline

2026-04-02
Gbhackers and Cybersecuritynews report on new Akira-like ransomware campaign.

More articles in this cluster (2)

Following this threat?

Track Akira in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed