Back to Resources

SentinelOne Demo: SentinelOne VS Megazord (Akira Variant) Ransomware – Detection and Remediation

In this video demonstration, we show how the SentinelOne Singularity XDR Platform protects against the Megazord ransomware, an Akira variant.

This variant emerged in August of 2023, with the group’s ransomware payloads written in Rust. These payloads also contain multiple pop-culture references to the Power Rangers entertainment and merchandising franchise. The internal naming in the Rust project is “Megazord”. Encrypted files are noted with the “POWERRANGES” extension. That same name is used for the ransom note text file as lower-case “powerranges.txt”.

Payload traits are also in line and share commonalities with Akira ransomware. There are multiple static similarities, along with code similarities between “Megazord” and “Akira.” It stands to reason that “Megazord” is an evolution or branch of Akira ransomware.

Victims are instructed to contact the attacker via TOX messenger. A unique Telegram channel link, along with the TOX messenger ID, are provided in the ransom note, dropped into each folder containing encrypted files.

The SentinelOne Singularity Platform can return systems to their original state.

Watch Now

Experience the World’s Most Advanced Cybersecurity Platform

See how our intelligent, autonomous cybersecurity platform harnesses the power of data and AI to protect your organization now and into the future.