# Akira Ransomware Attack Mapped by Huntress: RDP Initial Access, GOST Tunneling, Rclone Exfiltration

> Huntress analyzed an Akira ransomware intrusion that began with RDP access from a workstation not owned by the customer. The actor disabled BitDefender, dumped lsass.exe with procdump, deployed the GOST tunneling tool, exfiltrated data with Rclone, then removed volume shadow copies and ran Akira against multiple Shares subfolders.

- **Published:** 2026-10-10T00:00:00Z
- **Last reviewed:** 2026-10-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3186
- **ID:** TL-2026-3186
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)

## Description

In September 2026 the Huntress agent was deployed on an organization that had already been hit by an Akira ransomware attack. Forensic review of the impacted endpoint (Windows Event Logs, Shellbags, PowerShell logs and Akira log files) showed that the actor logged in over Remote Desktop Protocol (Terminal Services) from a workstation named C1IFRYXI that was not owned by the customer. The report does not state how the actor obtained access or credentials, and the source gives no threat actor attribution.

Once on the host, the actor opened the BitDefender console and stopped four BitDefender services (Endpoint Update, Endpoint Integration, Endpoint Protected and Endpoint Security services); Service Control Manager event 7036 recorded the terminations. The actor then ran procdump.exe from C:\PerfLogs against lsass.exe to harvest credentials. C:\PerfLogs is a world-writable directory that was used as the staging area for the actor's tools.

About four hours before encryption began, the actor deployed the open-source GOST (Go Simple Tunnel) proxy. It was dropped as C:\PerfLogs\Temp\svchost.exe, loaded a configuration from C:\PerfLogs\temp\config.dll, ran as SYSTEM, and tunneled to 64.227.4.134. Huntress assesses it was likely used for persistence. The actor also launched Rclone from C:\PerfLogs for file synchronization to cloud storage, which Huntress documents as the data exfiltration step. The destination configuration is not given in the source.

For impact, the actor ran PowerShell (powershell.exe -Command Get-WmiObject Win32_Shadowcopy , Remove-WmiObject) to delete volume shadow copies, then executed the Akira ransomware binary from C:\storage\win.exe in several runs against subfolders of a Shares folder. The actor checked the results through Windows Explorer. Malpedia catalogs the report under the families win.akira and elf.akira.

Background from the CISA advisory AA24-109A (published 2024-04-18, updated 2025-11-13): Akira operators target SMBs and organizations in education, manufacturing, IT, healthcare, financial services and food and agriculture. They use VPN and backup-software vulnerabilities for initial access, and use RDP, Rclone, procdump, Mimikatz, AnyDesk, WinRAR and Ngrok. Ransom notes are named fn.txt or akira_readme.txt, and encrypted files get extensions such as .akira, .powerranges, .akiranew or .aki. These CISA details are general Akira context and were not observed in the Huntress case.

## MITRE ATT&CK

- T1078 Valid Accounts
- T1021.001 Remote Services: Remote Desktop Protocol
- T1685 Disable or Modify Tools
- T1003.001 OS Credential Dumping: LSASS Memory
- T1574.001 Hijack Execution Flow: DLL
- T1036.005 Masquerading: Match Legitimate Resource Name or Location
- T1572 Protocol Tunneling
- T1090 Proxy
- T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
- T1020 Automated Exfiltration
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1490 Inhibit System Recovery
- T1489 Service Stop

## Sources

- [Up a Creek Without a Command Line: Mapping an Akira Ransomware Attack (Huntress)](https://www.huntress.com/blog/mapping-akira-ransomware-attack)
- [Malpedia library entry (win.akira, elf.akira)](https://malpedia.caad.fkie.fraunhofer.de/library/243c65c9-e7fb-4517-b9ae-922946f04332/)
- [CISA #StopRansomware: Akira Ransomware (AA24-109A)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-109a)
- [Malware Spotlight: Akira Ransomware (Arete)](https://areteir.com/resources/malware-spotlight-akira-ransomware)
- [Threat Brief: Understanding Akira Ransomware (Qualys)](https://blog.qualys.com/vulnerabilities-threat-research/2024/10/02/threat-brief-understanding-akira-ransomware)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3186
