Threat reportRansomwareTL-2026-3186
Akira Ransomware Attack Mapped by Huntress: RDP Initial Access, GOST Tunneling, Rclone Exfiltration
Akira Ransomware Attack Mapped by Huntress (TL-2026-3186) is a high-severity ransomware operation, first published 2026-10-10. It has no confirmed attribution, affects Microsoft Windows (RDP / Terminal Services endpoints and file shares), maps to 13 MITRE ATT&CK techniques (T1003.001, T1020, T1021.001), and is covered by 9 detection rules and 15 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 13MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-3186
- Threat ID
- TL-2026-3186
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- education, manufacturing, information-technology, health, finance, food-and-agriculture
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in Akira Ransomware Attack Mapped by Huntress
Malware and tooling: elf.akira, win.akira, GOST, ProcDump, Rclone - S1040
How Akira Ransomware Attack Mapped by Huntress works
Huntress analyzed an Akira ransomware intrusion that began with RDP access from a workstation not owned by the customer. The actor disabled BitDefender, dumped lsass.exe with procdump, deployed the GOST tunneling tool, exfiltrated data with Rclone, then removed volume shadow copies and ran Akira against multiple Shares subfolders.
In September 2026 the Huntress agent was deployed on an organization that had already been hit by an Akira ransomware attack. Forensic review of the impacted endpoint (Windows Event Logs, Shellbags, PowerShell logs and Akira log files) showed that the actor logged in over Remote Desktop Protocol (Terminal Services) from a workstation named C1IFRYXI that was not owned by the customer. The report does not state how the actor obtained access or credentials, and the source gives no threat actor attribution.
Once on the host, the actor opened the BitDefender console and stopped four BitDefender services (Endpoint Update, Endpoint Integration, Endpoint Protected and Endpoint Security services); Service Control Manager event 7036 recorded the terminations. The actor then ran procdump.exe from C:\PerfLogs against lsass.exe to harvest credentials. C:\PerfLogs is a world-writable directory that was used as the staging area for the actor's tools.
About four hours before encryption began, the actor deployed the open-source GOST (Go Simple Tunnel) proxy. It was dropped as C:\PerfLogs\Temp\svchost.exe, loaded a configuration from C:\PerfLogs\temp\config.dll, ran as SYSTEM, and tunneled to 64.227.4.134. Huntress assesses it was likely used for persistence. The actor also launched Rclone from C:\PerfLogs for file synchronization to cloud storage, which Huntress documents as the data exfiltration step. The destination configuration is not given in the source.
For impact, the actor ran PowerShell (powershell.exe -Command Get-WmiObject Win32_Shadowcopy , Remove-WmiObject) to delete volume shadow copies, then executed the Akira ransomware binary from C:\storage\win.exe in several runs against subfolders of a Shares folder. The actor checked the results through Windows Explorer. Malpedia catalogs the report under the families win.akira and elf.akira.
Background from the CISA advisory AA24-109A (published 2024-04-18, updated 2025-11-13): Akira operators target SMBs and organizations in education, manufacturing, IT, healthcare, financial services and food and agriculture. They use VPN and backup-software vulnerabilities for initial access, and use RDP, Rclone, procdump, Mimikatz, AnyDesk, WinRAR and Ngrok. Ransom notes are named fn.txt or akira_readme.txt, and encrypted files get extensions such as .akira, .powerranges, .akiranew or .aki. These CISA details are general Akira context and were not observed in the Huntress case.
MITRE ATT&CK techniques used in TL-2026-3186
Credential Access
T1003.001 OS Credential Dumping: LSASS Memory
Exfiltration
T1020 Automated Exfiltration; T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
Lateral Movement
T1021.001 Remote Services: Remote Desktop Protocol
Defense Evasion
T1036.005 Masquerading: Match Legitimate Resource Name or Location
Execution
T1059.001 Command and Scripting Interpreter: PowerShell
Initial Access
Command and Control
T1090 Proxy; T1572 Protocol Tunneling
Impact
T1489 Service Stop; T1490 Inhibit System Recovery
stealth
T1574.001 Hijack Execution Flow: DLL
defense-impairment
Affected products and versions in Akira Ransomware Attack Mapped by Huntress
- Microsoft — Windows (RDP / Terminal Services endpoints and file shares)
Vulnerable versions: Systems exposing RDP without MFA - Bitdefender — Bitdefender Endpoint Security (services stopped via console by the actor)
Vulnerable versions: Deployments without tamper protection or console access control
Remediation for Akira Ransomware Attack Mapped by Huntress
Immediate actions
- Block outbound traffic to 64.227.4.134 and hunt for connections to it
- Hunt for executables and tools (procdump.exe, rclone, svchost.exe, config.dll) in C:\PerfLogs and C:\PerfLogs\Temp
- Review RDP logon events (Terminal Services) for source workstations not in the asset inventory, such as C1IFRYXI
- Alert on stops of Bitdefender Endpoint services (SCM event 7036)
- Isolate hosts showing lsass.exe dumping, GOST tunneling or Rclone execution
Workarounds
- Restrict write and execute permissions on C:\PerfLogs
- Block unsanctioned tunneling and cloud-sync tools (GOST, Rclone) with application control
Longer-term hardening
- Enforce phishing-resistant MFA on all remote access including RDP
- Keep an accurate asset inventory and restrict RDP to managed workstations
- Enable tamper protection on endpoint security products
- Protect LSASS (credential protection) and monitor process access to lsass.exe
- Maintain offline, tested backups and segment the network
- Apply attack surface reduction rules
Timeline of Akira Ransomware Attack Mapped by Huntress
- CISA publishes joint advisory AA24-109A on Akira ransomware TTPs, tools (Rclone, procdump) and IOCs
- CISA significantly updates AA24-109A with new CVEs, TTPs and ransom note/extension details
- September 2026: shadow copies removed via PowerShell; Akira (C:\storage\win.exe) run several times against Shares subfolders
- September 2026: Rclone launched from C:\PerfLogs for cloud file synchronization (data exfiltration)
- September 2026: GOST deployed as C:\PerfLogs\Temp\svchost.exe with config.dll about 4 hours before encryption began
- September 2026: procdump.exe is run from C:\PerfLogs against lsass.exe
- September 2026: actor opens the BitDefender console and stops four Bitdefender Endpoint services (SCM event 7036 logged)
- September 2026 (exact day not published): actor logs in via RDP to the endpoint from non-customer workstation C1IFRYXI
- Huntress publishes 'Up a Creek Without a Command Line: Mapping an Akira Ransomware Attack'; Malpedia catalogs it the same day
Sources cited for Akira Ransomware Attack Mapped by Huntress
Detection coverage for TL-2026-3186
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3186 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.