# Akira Ransomware Attack Reconstructed: RDP Access, Procdump Credential Dumping, GOST Tunnel, Rclone Exfiltration

> Huntress reconstructed an Akira ransomware intrusion from Registry artifacts, Event Logs and ransomware logs after its agent was deployed post-compromise. The actor logged in over RDP from an external workstation, stopped Bitdefender services, dumped credentials with procdump.exe, staged Rclone and a GOST tunnel from C:\PerfLogs, deleted shadow copies via PowerShell and encrypted network share folders.

- **Published:** 2026-10-07T00:00:00Z
- **Last reviewed:** 2026-10-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2990
- **ID:** TL-2026-2990
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** Akira
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Huntress published a post-incident reconstruction of an Akira ransomware intrusion on 2026-10-06. The Huntress agent was only deployed in early September, after the compromise, so the investigation relied on forensic artifacts: Windows Event Logs, Registry Shellbags (which showed the actor's navigation through user directories), PowerShell event logs and the Akira ransomware log files.

Access was via Remote Desktop Protocol from an external workstation named C1IFRYXI to a domain controller in a domain-based environment with multiple file shares. The report does not say how the RDP credentials were obtained, whether a VPN was involved, or the victim's sector. After logging in, the actor opened the Bitdefender console and stopped several antivirus services through the Service Control Manager, including the Bitdefender Endpoint Update Service.

The actor then ran procdump.exe from C:\PerfLogs to dump credentials (LSASS memory). Rclone, also run from C:\PerfLogs, was used to sync data to cloud storage for exfiltration. A GOST (Go Simple Tunnel) binary was dropped as C:\PerfLogs\temp\svchost.exe with a config.dll configuration file and connected to 64.227.4.134. Huntress dates the tunnel to about four hours away from the start of the encryption processes (the report text says four hours after encryption started; the hunt summary says before), so the exact ordering should be treated as approximate. The ransomware binary C:\storage\win.exe was run as SYSTEM against the Shares folders. Volume shadow copies were removed with powershell.exe -Command Get-WmiObject Win32_Shadowcopy | Remove-WmiObject.

The report notes that Akira affiliates have used tunneling utilities before (CISA documents Ngrok; Mandiant reported UNC5330 using GOST in 2024). The joint CISA/FBI/Europol/NCSC-NL advisory AA24-109A (published 2024-04-18, updated 2025-11-13) describes Akira's wider tradecraft: initial access through VPNs without MFA, exploitation of internet-facing applications (for example CVE-2024-40766 SonicWall), spearphishing and valid accounts; exfiltration with Rclone, WinSCP and FileZilla; ChaCha20 plus RSA hybrid encryption; ransom notes fn.txt or akira_readme.txt; and extensions .akira, .powerranges, .akiranew and .aki. Those CISA details are background and were not confirmed for this specific intrusion.

Defender takeaways from Huntress: keep a full asset inventory, require MFA on remote access, monitor RDP from unknown workstations, watch C:\PerfLogs and similar directories for executable creation and launches, and deploy EDR before an incident so telemetry exists.

## MITRE ATT&CK

- T1133 External Remote Services
- T1021.001 Remote Desktop Protocol
- T1685 Disable or Modify Tools
- T1489 Service Stop
- T1003.001 LSASS Memory
- T1059.001 PowerShell
- T1572 Protocol Tunneling
- T1140 Deobfuscate/Decode Files or Information
- T1567.002 Exfiltration to Cloud Storage
- T1490 Inhibit System Recovery

## Sources

- [Up a Creek Without a Command Line: Mapping an Akira Ransomware Attack](https://www.huntress.com/blog/mapping-akira-ransomware-attack)
- [CISA AA24-109A: #StopRansomware: Akira Ransomware](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-109a)
- [FBI IC3 Joint Cybersecurity Advisory: #StopRansomware Akira (PDF)](https://www.ic3.gov/CSA/2024/240418.pdf)
- [AHA: Joint Cybersecurity Advisory #StopRansomware Akira Ransomware](https://www.aha.org/cybersecurity-government-intelligence-reports/2024-04-18-joint-cybersecurity-advisory-stopransomware-akira-ransomware)
- [AttackIQ: Response to CISA Advisory AA24-109A Akira Ransomware](https://www.attackiq.com/2024/04/22/response-to-cisa-advisory-aa24-109a-stopransomware-akira-ransomware/)
- [WaterISAC: CISA and Partners Release Advisory Update on Akira Ransomware](https://www.waterisac.org/tlpclear-joint-cybersecurity-advisory-cisa-and-partners-release-advisory-update-on-akira-ransomware)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2990
