Akatsuki cloud
Akatsuki Legion

 AKATSUKI  ·  DAYBREAK

The watch is kept before first light.

We are an independent research collective. We track adversary infrastructure, take apart intrusion campaigns, and publish the methodology alongside the findings so defenders can reproduce the work, not just read about it.

3 published reports Independent Open methodology & indicators

POWERED BY HUNT.IO

What we do

FOUR PRACTICES

Adversary tracking

We follow infrastructure rather than names. Domain impersonation patterns, JARM fingerprints, ASN correlation and hosting reuse — the artefacts an actor cannot easily discard between campaigns.

Evidence — Scattered Spider

Campaign analysis

End-to-end reconstruction of intrusion campaigns: initial access, lure design, execution chain, and the detection opportunities each stage leaves behind.

Evidence — Operation Black Mirror

Breach & blockchain forensics

Post-incident analysis of financial-sector compromise, including on-chain tracing of stolen funds and reconstruction of the attacker's path through internal systems.

Evidence — Nobitex

Detection engineering

Hunting queries and detection logic released with every report, so a finding becomes something you can run rather than something you have to trust.

In progress — release date not yet set

Selected research

2025

Work with us

We are open to research partnerships, sponsorship of published work, conference collaboration, and applications from analysts who want to publish under their own name.