Huntress Reconstructs an Akira Ransomware Attack from Forensic Artifacts

· Original article ↗

Summary

Huntress analysts reconstructed parts of an Akira ransomware attack using endpoint artifacts after its agent was installed post-compromise, limiting telemetry. They traced RDP access, antivirus shutdown, suspected credential dumping, tunneling and file-encryption clues.

Key points

  • The Huntress agent was installed after the compromise, limiting visibility into initial access and earlier attacker activity.
  • Windows Event Logs showed access to an endpoint via RDP from a workstation not owned by the organization.
  • The attacker stopped Bitdefender services and ran procdump, apparently to dump credentials from LSASS.
  • The attacker deployed GOST tunneling software, likely for persistence, then ran Rclone, which attackers use for data exfiltration.
  • Registry Shellbags, Akira logs and PowerShell events provided evidence of ransomware activity, including shadow-copy removal and repeated targeting of shared folders.
  • Huntress recommends MFA for exposed remote access, monitoring access from suspicious workstations, and watching C:\PerfLogs for suspicious files and executables.

Article Details

Attack Vectors
  • The threat actor accessed an impacted endpoint through RDP from a workstation not owned by the customer.
  • The actor accessed the BitDefender console, after which several Bitdefender endpoint services stopped.
  • The actor ran procdump.exe from C:\PerfLogs, presumably to dump lsass.exe for credential theft.
  • The actor deployed a GOST tunnel, likely for persistence, and launched RClone from C:\PerfLogs for data exfiltration.
  • Akira ransomware targeted folders beneath a Shares folder. A concurrent PowerShell command removed volume shadow copies.
Defensive Notes
  • Maintain an accurate inventory of physical systems, virtual systems, and applications, and reduce the attack surface.
  • Require MFA for remote access that must remain exposed.
  • Monitor access from unknown, suspicious, or known malicious workstations.
  • Monitor folders such as C:\PerfLogs for newly created files and executables.

Indicators of compromise

TypeIndicatorContext
IPV464[.]227[.]4[.]134GOST tunnel C2 address identified in the IOC table.
SHA2561f1bb322591b6d27fd2946e373d7d2efc2f4e1e66818846060d391600b600fbaSHA-256 of the ransomware executable listed as C:\storage\win.exe.
SHA256d00833318a04caa019c6f95dcb3598ad947d405010bfb2f3cbd04530a00bc3a4SHA-256 of the GOST tunnel executable listed as C:\PerfLogs\temp\svchost.exe.

MITRE ATT&CK

People

Threat Actors

Malware

Vendors

Products

Tools

Countries

Related Articles