Threat reportRansomwareTL-2026-2990

Akira Ransomware Attack Reconstructed: RDP Access, Procdump Credential Dumping, GOST Tunnel, Rclone Exfiltration

highACTIVE

Akira Ransomware Attack Reconstructed (TL-2026-2990) is a high-severity ransomware operation, first published 2026-10-07. It is attributed to Akira with medium confidence, affects Microsoft Windows domain environment (domain controller, file shares), maps to 10 MITRE ATT&CK techniques (T1003.001, T1021.001, T1059.001), and is covered by 9 detection rules and 18 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
10MITRE ATT&CK
Actors
1Akira
Detection rules
9SPL · KQL · Sigma
IOCs
18Indicators of compromise

Key facts for TL-2026-2990

Threat ID
TL-2026-2990
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution
Akira
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
critical infrastructure, business
Target regions
North America, Europe, australia
Detection rules
9
Indicators of compromise
18

Malware and tooling in Akira Ransomware Attack Reconstructed

Malware and tooling: Akira, GOST, ProcDump, Rclone - S1040

How Akira Ransomware Attack Reconstructed works

Huntress reconstructed an Akira ransomware intrusion from Registry artifacts, Event Logs and ransomware logs after its agent was deployed post-compromise. The actor logged in over RDP from an external workstation, stopped Bitdefender services, dumped credentials with procdump.exe, staged Rclone and a GOST tunnel from C:\PerfLogs, deleted shadow copies via PowerShell and encrypted network share folders.

Huntress published a post-incident reconstruction of an Akira ransomware intrusion on 2026-10-06. The Huntress agent was only deployed in early September, after the compromise, so the investigation relied on forensic artifacts: Windows Event Logs, Registry Shellbags (which showed the actor's navigation through user directories), PowerShell event logs and the Akira ransomware log files.

Access was via Remote Desktop Protocol from an external workstation named C1IFRYXI to a domain controller in a domain-based environment with multiple file shares. The report does not say how the RDP credentials were obtained, whether a VPN was involved, or the victim's sector. After logging in, the actor opened the Bitdefender console and stopped several antivirus services through the Service Control Manager, including the Bitdefender Endpoint Update Service.

The actor then ran procdump.exe from C:\PerfLogs to dump credentials (LSASS memory). Rclone, also run from C:\PerfLogs, was used to sync data to cloud storage for exfiltration. A GOST (Go Simple Tunnel) binary was dropped as C:\PerfLogs\temp\svchost.exe with a config.dll configuration file and connected to 64.227.4.134. Huntress dates the tunnel to about four hours away from the start of the encryption processes (the report text says four hours after encryption started; the hunt summary says before), so the exact ordering should be treated as approximate. The ransomware binary C:\storage\win.exe was run as SYSTEM against the Shares folders. Volume shadow copies were removed with powershell.exe -Command Get-WmiObject Win32_Shadowcopy | Remove-WmiObject.

The report notes that Akira affiliates have used tunneling utilities before (CISA documents Ngrok; Mandiant reported UNC5330 using GOST in 2024). The joint CISA/FBI/Europol/NCSC-NL advisory AA24-109A (published 2024-04-18, updated 2025-11-13) describes Akira's wider tradecraft: initial access through VPNs without MFA, exploitation of internet-facing applications (for example CVE-2024-40766 SonicWall), spearphishing and valid accounts; exfiltration with Rclone, WinSCP and FileZilla; ChaCha20 plus RSA hybrid encryption; ransom notes fn.txt or akira_readme.txt; and extensions .akira, .powerranges, .akiranew and .aki. Those CISA details are background and were not confirmed for this specific intrusion.

Defender takeaways from Huntress: keep a full asset inventory, require MFA on remote access, monitor RDP from unknown workstations, watch C:\PerfLogs and similar directories for executable creation and launches, and deploy EDR before an incident so telemetry exists.

MITRE ATT&CK techniques used in TL-2026-2990

Credential Access

T1003.001 LSASS Memory

Lateral Movement

T1021.001 Remote Desktop Protocol

Execution

T1059.001 PowerShell

Initial Access

T1133 External Remote Services

Stealth

T1140 Deobfuscate/Decode Files or Information

Impact

T1489 Service Stop; T1490 Inhibit System Recovery

Exfiltration

T1567.002 Exfiltration to Cloud Storage

Command and Control

T1572 Protocol Tunneling

Defense Impairment

T1685 Disable or Modify Tools

Affected products and versions in Akira Ransomware Attack Reconstructed

  • Microsoft — Windows domain environment (domain controller, file shares) with exposed RDP

Remediation for Akira Ransomware Attack Reconstructed

Patches

  • Apply patches for CVEs listed in CISA AA24-109A that apply to your environment (not confirmed as used in this intrusion)

Immediate actions

  • Block 64.227.4.134 at the perimeter and hunt for it in proxy and firewall logs
  • Hunt for executables in C:\PerfLogs, C:\PerfLogs\temp and C:\storage, and for svchost.exe running outside System32
  • Alert on procdump.exe accessing lsass.exe and on Rclone execution
  • Review RDP logons from unknown workstation names such as C1IFRYXI

Workarounds

  • Do not expose RDP directly to the internet; restrict to VPN or a gateway with MFA
  • Restrict who can stop AV services and who can run dump tools on domain controllers

Longer-term hardening

  • Require MFA on all remote access including RDP gateways and VPN
  • Deploy EDR before an incident and keep tamper protection on AV services
  • Maintain an asset inventory and reduce internet-exposed attack surface
  • Keep offline, immutable backups; monitor for Win32_Shadowcopy removal via PowerShell/WMI

Timeline of Akira Ransomware Attack Reconstructed

  • Akira ransomware activity begins (CISA: impacting organizations since March 2023, initially Windows-focused)
  • Akira threat actors deploy a Linux variant targeting VMware ESXi virtual machines (April 2023, per CISA)
  • Akira_v2 (Rust) and Megazord (Rust) variants appear in August 2023, per CISA
  • CISA, FBI, Europol EC3 and NCSC-NL publish joint advisory AA24-109A on Akira TTPs and IOCs
  • AA24-109A updated with new Akira activity and targeting of Nutanix AHV
  • Approximate period of the intrusion: RDP login from C1IFRYXI, Bitdefender services stopped, procdump LSASS dump, Rclone exfiltration, GOST tunnel to 64.227.4.134 about four hours from encryption start, shadow copies deleted, Shares encrypted (exact dates not published)
  • Huntress agent deployed on the victim environment after the compromise (report says 'early September'; exact day not given)
  • Huntress publishes 'Up a Creek Without a Command Line: Mapping an Akira Ransomware Attack'

Sources cited for Akira Ransomware Attack Reconstructed

Detection coverage for TL-2026-2990

As of 2026-10-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2990 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
18 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats