Threat reportRansomwareTL-2026-2990
Akira Ransomware Attack Reconstructed: RDP Access, Procdump Credential Dumping, GOST Tunnel, Rclone Exfiltration
Akira Ransomware Attack Reconstructed (TL-2026-2990) is a high-severity ransomware operation, first published 2026-10-07. It is attributed to Akira with medium confidence, affects Microsoft Windows domain environment (domain controller, file shares), maps to 10 MITRE ATT&CK techniques (T1003.001, T1021.001, T1059.001), and is covered by 9 detection rules and 18 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 10MITRE ATT&CK
- Actors
- 1Akira
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 18Indicators of compromise
Key facts for TL-2026-2990
- Threat ID
- TL-2026-2990
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- Akira
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- critical infrastructure, business
- Target regions
- North America, Europe, australia
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in Akira Ransomware Attack Reconstructed
Malware and tooling: Akira, GOST, ProcDump, Rclone - S1040
How Akira Ransomware Attack Reconstructed works
Huntress reconstructed an Akira ransomware intrusion from Registry artifacts, Event Logs and ransomware logs after its agent was deployed post-compromise. The actor logged in over RDP from an external workstation, stopped Bitdefender services, dumped credentials with procdump.exe, staged Rclone and a GOST tunnel from C:\PerfLogs, deleted shadow copies via PowerShell and encrypted network share folders.
Huntress published a post-incident reconstruction of an Akira ransomware intrusion on 2026-10-06. The Huntress agent was only deployed in early September, after the compromise, so the investigation relied on forensic artifacts: Windows Event Logs, Registry Shellbags (which showed the actor's navigation through user directories), PowerShell event logs and the Akira ransomware log files.
Access was via Remote Desktop Protocol from an external workstation named C1IFRYXI to a domain controller in a domain-based environment with multiple file shares. The report does not say how the RDP credentials were obtained, whether a VPN was involved, or the victim's sector. After logging in, the actor opened the Bitdefender console and stopped several antivirus services through the Service Control Manager, including the Bitdefender Endpoint Update Service.
The actor then ran procdump.exe from C:\PerfLogs to dump credentials (LSASS memory). Rclone, also run from C:\PerfLogs, was used to sync data to cloud storage for exfiltration. A GOST (Go Simple Tunnel) binary was dropped as C:\PerfLogs\temp\svchost.exe with a config.dll configuration file and connected to 64.227.4.134. Huntress dates the tunnel to about four hours away from the start of the encryption processes (the report text says four hours after encryption started; the hunt summary says before), so the exact ordering should be treated as approximate. The ransomware binary C:\storage\win.exe was run as SYSTEM against the Shares folders. Volume shadow copies were removed with powershell.exe -Command Get-WmiObject Win32_Shadowcopy | Remove-WmiObject.
The report notes that Akira affiliates have used tunneling utilities before (CISA documents Ngrok; Mandiant reported UNC5330 using GOST in 2024). The joint CISA/FBI/Europol/NCSC-NL advisory AA24-109A (published 2024-04-18, updated 2025-11-13) describes Akira's wider tradecraft: initial access through VPNs without MFA, exploitation of internet-facing applications (for example CVE-2024-40766 SonicWall), spearphishing and valid accounts; exfiltration with Rclone, WinSCP and FileZilla; ChaCha20 plus RSA hybrid encryption; ransom notes fn.txt or akira_readme.txt; and extensions .akira, .powerranges, .akiranew and .aki. Those CISA details are background and were not confirmed for this specific intrusion.
Defender takeaways from Huntress: keep a full asset inventory, require MFA on remote access, monitor RDP from unknown workstations, watch C:\PerfLogs and similar directories for executable creation and launches, and deploy EDR before an incident so telemetry exists.
MITRE ATT&CK techniques used in TL-2026-2990
Credential Access
Lateral Movement
T1021.001 Remote Desktop Protocol
Execution
Initial Access
T1133 External Remote Services
Stealth
T1140 Deobfuscate/Decode Files or Information
Impact
T1489 Service Stop; T1490 Inhibit System Recovery
Exfiltration
T1567.002 Exfiltration to Cloud Storage
Command and Control
Defense Impairment
Affected products and versions in Akira Ransomware Attack Reconstructed
- Microsoft — Windows domain environment (domain controller, file shares) with exposed RDP
Remediation for Akira Ransomware Attack Reconstructed
Patches
- Apply patches for CVEs listed in CISA AA24-109A that apply to your environment (not confirmed as used in this intrusion)
Immediate actions
- Block 64.227.4.134 at the perimeter and hunt for it in proxy and firewall logs
- Hunt for executables in C:\PerfLogs, C:\PerfLogs\temp and C:\storage, and for svchost.exe running outside System32
- Alert on procdump.exe accessing lsass.exe and on Rclone execution
- Review RDP logons from unknown workstation names such as C1IFRYXI
Workarounds
- Do not expose RDP directly to the internet; restrict to VPN or a gateway with MFA
- Restrict who can stop AV services and who can run dump tools on domain controllers
Longer-term hardening
- Require MFA on all remote access including RDP gateways and VPN
- Deploy EDR before an incident and keep tamper protection on AV services
- Maintain an asset inventory and reduce internet-exposed attack surface
- Keep offline, immutable backups; monitor for Win32_Shadowcopy removal via PowerShell/WMI
Timeline of Akira Ransomware Attack Reconstructed
- Akira ransomware activity begins (CISA: impacting organizations since March 2023, initially Windows-focused)
- Akira threat actors deploy a Linux variant targeting VMware ESXi virtual machines (April 2023, per CISA)
- Akira_v2 (Rust) and Megazord (Rust) variants appear in August 2023, per CISA
- CISA, FBI, Europol EC3 and NCSC-NL publish joint advisory AA24-109A on Akira TTPs and IOCs
- AA24-109A updated with new Akira activity and targeting of Nutanix AHV
- Approximate period of the intrusion: RDP login from C1IFRYXI, Bitdefender services stopped, procdump LSASS dump, Rclone exfiltration, GOST tunnel to 64.227.4.134 about four hours from encryption start, shadow copies deleted, Shares encrypted (exact dates not published)
- Huntress agent deployed on the victim environment after the compromise (report says 'early September'; exact day not given)
- Huntress publishes 'Up a Creek Without a Command Line: Mapping an Akira Ransomware Attack'
Sources cited for Akira Ransomware Attack Reconstructed
- Up a Creek Without a Command Line: Mapping an Akira Ransomware Attack
- CISA AA24-109A: #StopRansomware: Akira Ransomware
- FBI IC3 Joint Cybersecurity Advisory: #StopRansomware Akira (PDF)
- AHA: Joint Cybersecurity Advisory #StopRansomware Akira Ransomware
- AttackIQ: Response to CISA Advisory AA24-109A Akira Ransomware
- WaterISAC: CISA and Partners Release Advisory Update on Akira Ransomware
Detection coverage for TL-2026-2990
As of 2026-10-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2990 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.