Akatsuki cloud
Akatsuki Legion

Everything we've published.

Every report, in one place methodology and indicators included, not just findings.

Inside PlayCrypt: Deconstructing the Amadey → Cobalt Strike → Play Multi-Stage Ransomware Chain

One file hash. A few pivots. That's all it took to walk straight into Play ransomware's back office: a Cobalt Strike server on Tencent loaded with exploit and credential-theft scripts, a live Sliver C2 host, and a team server actively churning out evasive Windows payloads, all sitting in open directories, no victim network required. A misconfigured leak site handed over Play's negotiation timelines for free. And one intrusion traced back to a single binary carrying Amadey, Cobalt Strike, Elex, and the Play encryptor together, proof that if you're only watching the network, you're already too late.

APTPlay RansomwareAdversary Infrastructure HuntingMalware AnalysisThreat IntelligenceCTICybersecurityCobalt StrikeSilver C2AmadeyThreat HuntingDark web
AUG 14, 2026

Scattered Spider: Many Names, One Syndicate

A financially motivated collective that weaponises social engineering over malware, mapped through domain impersonation, JARM pivoting and IOC clustering.

CybercrimeSocial EngineeringThreat HuntingThreat Intelligence
18 DEC 2025

Operation Black Mirror: ClickFix Campaign Analysis

Multi-campaign analysis of ClickFix operations run by both APT actors and crimeware crews, focused on Win+R lures and infrastructure-level hunting.

APTMalwareThreat HuntingClickFix
20 NOV 2025

When the Bazaar Burned From Within: The Silent Breach of Nobitex

How a cryptocurrency exchange was taken apart from the inside, and what its internal architecture revealed once the attackers published it.

Breach AnalysisCryptocurrencyThreat IntelligenceForensics
02 SEP 2025