Huntress Reconstructs an Akira Ransomware Attack from Forensic Artifacts

Summary
Huntress analysts reconstructed parts of an Akira ransomware attack using endpoint artifacts after its agent was installed post-compromise, limiting telemetry. They traced RDP access, antivirus shutdown, suspected credential dumping, tunneling and file-encryption clues.
Key points
- The Huntress agent was installed after the compromise, limiting visibility into initial access and earlier attacker activity.
- Windows Event Logs showed access to an endpoint via RDP from a workstation not owned by the organization.
- The attacker stopped Bitdefender services and ran procdump, apparently to dump credentials from LSASS.
- The attacker deployed GOST tunneling software, likely for persistence, then ran Rclone, which attackers use for data exfiltration.
- Registry Shellbags, Akira logs and PowerShell events provided evidence of ransomware activity, including shadow-copy removal and repeated targeting of shared folders.
- Huntress recommends MFA for exposed remote access, monitoring access from suspicious workstations, and watching C:\PerfLogs for suspicious files and executables.
Article Details
- Attack Vectors
- The threat actor accessed an impacted endpoint through RDP from a workstation not owned by the customer.
- The actor accessed the BitDefender console, after which several Bitdefender endpoint services stopped.
- The actor ran procdump.exe from C:\PerfLogs, presumably to dump lsass.exe for credential theft.
- The actor deployed a GOST tunnel, likely for persistence, and launched RClone from C:\PerfLogs for data exfiltration.
- Akira ransomware targeted folders beneath a Shares folder. A concurrent PowerShell command removed volume shadow copies.
- Defensive Notes
- Maintain an accurate inventory of physical systems, virtual systems, and applications, and reduce the attack surface.
- Require MFA for remote access that must remain exposed.
- Monitor access from unknown, suspicious, or known malicious workstations.
- Monitor folders such as C:\PerfLogs for newly created files and executables.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 64[.]227[.]4[.]134 | GOST tunnel C2 address identified in the IOC table. |
| SHA256 | 1f1bb322591b6d27fd2946e373d7d2efc2f4e1e66818846060d391600b600fba | SHA-256 of the ransomware executable listed as C:\storage\win.exe. |
| SHA256 | d00833318a04caa019c6f95dcb3598ad947d405010bfb2f3cbd04530a00bc3a4 | SHA-256 of the GOST tunnel executable listed as C:\PerfLogs\temp\svchost.exe. |
MITRE ATT&CK
T1003.001 · LSASS MemoryThe actor ran procdump.exe; Huntress assessed that it was presumably used to dump lsass.exe for credential theft.T1021.001 · Remote Desktop ProtocolWindows Event Logs showed the actor accessing the impacted endpoint through RDP.T1059.001 · PowerShellPowerShell Event Logs recorded a command that removed volume shadow copies during the ransomware activity.T1486 · Data Encrypted for ImpactAkira log files and forensic artifacts indicated ransomware execution against folders beneath a Shares folder.T1490 · Inhibit System RecoveryA PowerShell command used Get-WmiObject Win32_Shadowcopy and Remove-WmiObject to remove volume shadow copies.T1562.001 · Disable or Modify ToolsSeveral Bitdefender endpoint protection services stopped after the actor accessed the BitDefender console.T1572 · Protocol TunnelingThe actor deployed a GOST tunnel; the article's IOC table identifies a GOST tunnel C2 address.
People
Threat Actors
Malware
Vendors
Bitdefenderfrom a workstation not owned by the customer. Shortly after, the threat actor accessed the BitDefender console, and several Windows services associated with the antivirus application were stopped:HuntressIn September, the Huntress agent was deployed on an organization that had been hit by an Akira ransomware attack. The post-compromise agent deployment limited Huntress visibility into critical pieces of evidence.
Products
Bitdefenderfrom a workstation not owned by the customer. Shortly after, the threat actor accessed the BitDefender console, and several Windows services associated with the antivirus application were stopped:Huntress agentIn September, the Huntress agent was deployed on an organization that had been hit by an Akira ransomware attack. The post-compromise agent deployment limited Huntress visibility into critical pieces of evidence. Microsoft Windowsour researchers had to make do with what was available from the impacted endpoints: a mixed bag of Windows Registry artifacts, Windows Event Logs, and Akira log files. However, these artifacts helped paint a
Tools
GOSTThe actor also deployed a GOST tunneling tool, likely for persistence.Ngrokaffiliates have also been found establishing C2 communications with further tunneling utilities like Ngrok to initiate encrypted sessions that attempt to bypass perimeter monitoring.procdump.exeThen, procdump.exe was run from the C:\PerfLogs folder, presumably to perform credential theft by dumping the contents of the lsass.exe process. This then deployed the GOST tunnel tool.RClonethe attack accessed the endpoint via Remote Desktop Protocol (RDP), disabled antivirus, and deployed Rclone for data exfiltration, before deploying the ransomware.