Skip to content

Image: cdn.builder.io · rights & removal

Executive Summary

Huntress researchers investigated activity following the deployment of a Huntress agent on an organization targeted by an Akira ransomware attack. The investigation utilized artifacts from endpoints, including Windows Registry data, Event Logs, and Akira log files, to reconstruct parts of the incident timeline. Initial EDR signals observed activity related to svchost.exe execution from C:\PerfLogs\Temp\ under the SYSTEM account, loading config.dll. Subsequent analysis revealed that a threat actor accessed an endpoint via Terminal Services/RDP from an external workstation and stopped several BitDefender antivirus services. The actor then executed procdump.exe from C:\PerfLogs to potentially collect credentials from lsass.exe before deploying the GOST tunnel tool for persistence. Four hours after file encryption, a GOST tunneling tool was deployed. Later activities involved launching RClone for potential data exfiltration and observing Shellbags artifacts indicating access to Shares folder subfolders before ransomware execution. A sequence of operations involving launching the ransomware, creating Akira log files, and accessing target folders via Windows Explorer occurred multiple times.

Facts Only

* Huntress agent was installed in early September on an organization targeted by an Akira ransomware attack.
* An EDR signal showed svchost.exe executed from C:\PerfLogs\Temp\ under the SYSTEM account, loading config.dll.
* The threat actor accessed the impacted endpoint via Terminal Services/RDP from a workstation not owned by the customer.
* Several BitDefender services were stopped: Service Control Manager/7036;Bitdefender Endpoint Update Service, Service Control Manager/7036;Bitdefender Endpoint Integration Service, and Service Control Manager/7036;Bitdefender Endpoint Protected Service, and Service Control Manager/7036;Bitdefender Endpoint Security Service.
* procdump.exe was run from C:\PerfLogs to presumably dump lsass.exe contents for credential theft.
* The GOST tunnel tool was deployed approximately four hours after file encryption processes began.
* RClone was launched from C:\PerfLogs following the deployment of the GOST tunnel.
* Shellbags artifacts indicated access to Shares folder subfolders before launching the first Akira command.
* A PowerShell command involving Get-WmiObject Win32Shadowcopy and Remove-WmiObject correlated with an Akira log file creation, indicating ransomware launch against the Shares folder.
* Shellbags artifacts showed repeated access to Shares folder subfolders following ransomware launch.

Full Take

The narrative demonstrates a critical gap between artifact availability and complete telemetry, forcing investigators to rely on "toolmark" evidence derived from post-compromise actions rather than initial intrusion events. The progression of the observed activities—from remote access and credential dumping (using procdump) to establishing persistence via GOST tunneling, followed by data synchronization (RClone), and finally file encryption confirmed by Shellbag traces—suggests a methodical, multi-stage operation. This sequence implies that the lack of pre-installation telemetry limits the ability to fully map the initial access vector, but the subsequent actions still provide actionable intelligence regarding internal reconnaissance and exfiltration methods employed by the threat actor. The pattern seen in relating low-level artifact artifacts (Registry/Event Logs) with high-level adversary tools (Akira, GOST, RClone) suggests a playbook where operational steps are left behind to document success rather than initial failure. The reliance on these traces highlights the ongoing challenge for defenders: how to build comprehensive incident narratives when the most revealing evidence exists outside standard EDR streams, forcing a deeper inquiry into system artifacts as forensic sources.
Bridge Questions: Given the observed dependency on post-compromise artifact analysis, what systemic changes are required to ensure that baseline operational telemetry is prioritized and retained regardless of agent deployment status? How can organizations architect monitoring systems to correlate low-level system events with high-level adversary tool usage more natively during initial phases of compromise? What assumptions about attacker behavior, derived from these post-incident patterns, might be inadvertently overlooked when focusing solely on endpoint visibility post-installation?

From the original · Huntress Labs

Acknowledgments: Special thanks to Dray Agha for his extensive contributions to this investigation. Background In September, the Huntress agent was deployed on an organization that had been targeted in an Akira ransomware attack.
Read the full story at huntress.com

Sentinel — Human

Confidence

The text reads like an internal post-mortem or forensic report, blending highly specific technical findings with analytical context, strongly suggesting human authorship from an expert source.

Signals Detected
low severity: Varied sentence length and use of specialized investigative terminology suggests human authorship.
low severity: The text successfully weaves disparate technical findings into a cohesive narrative progression, demonstrating a flow driven by investigative goals rather than mere information delivery.
low severity: Use of specific artifact references (Registry, Event Logs, Akira logs) points to domain-specific knowledge that is typical of specialized reporting.
low severity: The detailed sequence of artifacts (Shellbags $ ightarrow$ PowerShell $ ightarrow$ Akira log creation) shows a process mapping that feels grounded in forensic methodology rather than broad generalization.
Human Indicators
Use of specific, nested artifact references and the 'archeology-style' approach to piecing together data suggests deep domain expertise characteristic of human investigation reporting.
The shift in focus between technical execution details (GOST tunneling) and high-level mitigation guidance demonstrates a narrative arc typical of investigative journalism or security analysis.
Up a Creek Without a Command Line: Mapping an Akira Ransomware Attack | Huntaegis