Threat reportRansomwareTL-2026-3186

Akira Ransomware Attack Mapped by Huntress: RDP Initial Access, GOST Tunneling, Rclone Exfiltration

highACTIVE

Akira Ransomware Attack Mapped by Huntress (TL-2026-3186) is a high-severity ransomware operation, first published 2026-10-10. It has no confirmed attribution, affects Microsoft Windows (RDP / Terminal Services endpoints and file shares), maps to 13 MITRE ATT&CK techniques (T1003.001, T1020, T1021.001), and is covered by 9 detection rules and 15 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
13MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-3186

Threat ID
TL-2026-3186
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
education, manufacturing, information-technology, health, finance, food-and-agriculture
Target regions
Global
Detection rules
9
Indicators of compromise
15

Malware and tooling in Akira Ransomware Attack Mapped by Huntress

Malware and tooling: elf.akira, win.akira, GOST, ProcDump, Rclone - S1040

How Akira Ransomware Attack Mapped by Huntress works

Huntress analyzed an Akira ransomware intrusion that began with RDP access from a workstation not owned by the customer. The actor disabled BitDefender, dumped lsass.exe with procdump, deployed the GOST tunneling tool, exfiltrated data with Rclone, then removed volume shadow copies and ran Akira against multiple Shares subfolders.

In September 2026 the Huntress agent was deployed on an organization that had already been hit by an Akira ransomware attack. Forensic review of the impacted endpoint (Windows Event Logs, Shellbags, PowerShell logs and Akira log files) showed that the actor logged in over Remote Desktop Protocol (Terminal Services) from a workstation named C1IFRYXI that was not owned by the customer. The report does not state how the actor obtained access or credentials, and the source gives no threat actor attribution.

Once on the host, the actor opened the BitDefender console and stopped four BitDefender services (Endpoint Update, Endpoint Integration, Endpoint Protected and Endpoint Security services); Service Control Manager event 7036 recorded the terminations. The actor then ran procdump.exe from C:\PerfLogs against lsass.exe to harvest credentials. C:\PerfLogs is a world-writable directory that was used as the staging area for the actor's tools.

About four hours before encryption began, the actor deployed the open-source GOST (Go Simple Tunnel) proxy. It was dropped as C:\PerfLogs\Temp\svchost.exe, loaded a configuration from C:\PerfLogs\temp\config.dll, ran as SYSTEM, and tunneled to 64.227.4.134. Huntress assesses it was likely used for persistence. The actor also launched Rclone from C:\PerfLogs for file synchronization to cloud storage, which Huntress documents as the data exfiltration step. The destination configuration is not given in the source.

For impact, the actor ran PowerShell (powershell.exe -Command Get-WmiObject Win32_Shadowcopy , Remove-WmiObject) to delete volume shadow copies, then executed the Akira ransomware binary from C:\storage\win.exe in several runs against subfolders of a Shares folder. The actor checked the results through Windows Explorer. Malpedia catalogs the report under the families win.akira and elf.akira.

Background from the CISA advisory AA24-109A (published 2024-04-18, updated 2025-11-13): Akira operators target SMBs and organizations in education, manufacturing, IT, healthcare, financial services and food and agriculture. They use VPN and backup-software vulnerabilities for initial access, and use RDP, Rclone, procdump, Mimikatz, AnyDesk, WinRAR and Ngrok. Ransom notes are named fn.txt or akira_readme.txt, and encrypted files get extensions such as .akira, .powerranges, .akiranew or .aki. These CISA details are general Akira context and were not observed in the Huntress case.

MITRE ATT&CK techniques used in TL-2026-3186

Credential Access

T1003.001 OS Credential Dumping: LSASS Memory

Exfiltration

T1020 Automated Exfiltration; T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

Lateral Movement

T1021.001 Remote Services: Remote Desktop Protocol

Defense Evasion

T1036.005 Masquerading: Match Legitimate Resource Name or Location

Execution

T1059.001 Command and Scripting Interpreter: PowerShell

Initial Access

T1078 Valid Accounts

Command and Control

T1090 Proxy; T1572 Protocol Tunneling

Impact

T1489 Service Stop; T1490 Inhibit System Recovery

stealth

T1574.001 Hijack Execution Flow: DLL

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Akira Ransomware Attack Mapped by Huntress

  • Microsoft — Windows (RDP / Terminal Services endpoints and file shares)
    Vulnerable versions: Systems exposing RDP without MFA
  • Bitdefender — Bitdefender Endpoint Security (services stopped via console by the actor)
    Vulnerable versions: Deployments without tamper protection or console access control

Remediation for Akira Ransomware Attack Mapped by Huntress

Immediate actions

  • Block outbound traffic to 64.227.4.134 and hunt for connections to it
  • Hunt for executables and tools (procdump.exe, rclone, svchost.exe, config.dll) in C:\PerfLogs and C:\PerfLogs\Temp
  • Review RDP logon events (Terminal Services) for source workstations not in the asset inventory, such as C1IFRYXI
  • Alert on stops of Bitdefender Endpoint services (SCM event 7036)
  • Isolate hosts showing lsass.exe dumping, GOST tunneling or Rclone execution

Workarounds

  • Restrict write and execute permissions on C:\PerfLogs
  • Block unsanctioned tunneling and cloud-sync tools (GOST, Rclone) with application control

Longer-term hardening

  • Enforce phishing-resistant MFA on all remote access including RDP
  • Keep an accurate asset inventory and restrict RDP to managed workstations
  • Enable tamper protection on endpoint security products
  • Protect LSASS (credential protection) and monitor process access to lsass.exe
  • Maintain offline, tested backups and segment the network
  • Apply attack surface reduction rules

Timeline of Akira Ransomware Attack Mapped by Huntress

  • CISA publishes joint advisory AA24-109A on Akira ransomware TTPs, tools (Rclone, procdump) and IOCs
  • CISA significantly updates AA24-109A with new CVEs, TTPs and ransom note/extension details
  • September 2026: shadow copies removed via PowerShell; Akira (C:\storage\win.exe) run several times against Shares subfolders
  • September 2026: Rclone launched from C:\PerfLogs for cloud file synchronization (data exfiltration)
  • September 2026: GOST deployed as C:\PerfLogs\Temp\svchost.exe with config.dll about 4 hours before encryption began
  • September 2026: procdump.exe is run from C:\PerfLogs against lsass.exe
  • September 2026: actor opens the BitDefender console and stops four Bitdefender Endpoint services (SCM event 7036 logged)
  • September 2026 (exact day not published): actor logs in via RDP to the endpoint from non-customer workstation C1IFRYXI
  • Huntress publishes 'Up a Creek Without a Command Line: Mapping an Akira Ransomware Attack'; Malpedia catalogs it the same day

Sources cited for Akira Ransomware Attack Mapped by Huntress

Detection coverage for TL-2026-3186

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3186 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats