Skip to content

Image: cdn.builder.io · rights & removal

Executive Summary

The investigation followed the deployment of a Huntress agent on an organization compromised by an Akira ransomware attack, noting that post-compromise installations may limit telemetry from earlier stages of the incident. Researchers pieced together information from Windows Registry artifacts, Event Logs, and Akira log files to reconstruct attacker activity. Evidence showed the threat actor accessed an endpoint via Remote Desktop/Terminal Services from an external workstation, stopped several Bitdefender services, executed procdump.exe from C:\PerfLogs, deployed a GOST tunneling tool for persistence, and then used RClone for file exfiltration. The timeline revealed that access to specific shared folders preceded the launch of Akira ransomware, with subsequent PowerShell commands related to shadow copy removal occurring concurrently with artifact creation.

Facts Only

* A Huntress agent was deployed on an organization targeted by an Akira ransomware attack in September.
* An EDR signal indicated svchost.exe executing from C:\PerfLogs\Temp\ under the SYSTEM account, loading config.dll.
* Windows Event Logs showed threat actor access via Terminal Services/RDP from a non-customer workstation.
* The threat actor stopped Bitdefender services: Service Control Manager/7036;Bitdefender Endpoint Update Service, Service Control Manager/7036;Bitdefender Endpoint Integration Service, and Service Control Manager/7036;Bitdefender Endpoint Protected Service, and Service Control Manager/7036;Bitdefender Endpoint Security Service.
* procdump.exe was run from C:\PerfLogs to potentially dump lsass.exe contents.
* The GOST tunnel tool was deployed approximately four hours after file encryption processes began for persistence.
* RClone was launched from the C:\PerfLogs folder following the deployment of the GOST tunnel.
* Shellbags artifacts indicated access to subfolders beneath a Shares folder before the first Akira command execution.
* PowerShell command line evidence indicated the launch of ransomware and creation of an Akira log file, followed by checking Shared folder subfolders via Windows Explorer three more times.

Full Take

The reconstruction relies heavily on circumstantial toolmarks—such as Shellbags artifacts and specific sequence correlations between system calls, registry entries, and malware logs—to establish a timeline of events when direct telemetry was limited. This reliance forces an understanding of how threat actors deliberately obfuscate the initial compromise phase, limiting forensic visibility to post-exploitation activities. The sequence detailing credential dumping via procdump, followed by deploying the GOST tunnel for C2 and subsequent data exfiltration using RClone, establishes a specific playbook that correlates known tactics used in Akira affiliate attacks with modern tunneling utilities like GOST and Ngrok. The pattern observed is one of layered obfuscation: initial access (RDP), privilege escalation/credential theft (procdump), establishment of persistence (GOST), and final exfiltration (RClone). The implication for defense is that focusing solely on endpoint detection post-installation misses the critical preparatory steps; resilience requires monitoring for these low-level, cross-artifact toolmarks across the entire system state. What are the hidden artifacts or less-monitored log sources that could reveal the pre-agent deployment activities? Where does the focus need to shift from post-compromise signal detection to proactive anomaly hunting within credential management and shadow copy usage?

From the original · Huntress Labs

Acknowledgments: Special thanks to Dray Agha for his extensive contributions to this investigation. Background In September, the Huntress agent was deployed on an organization that had been targeted in an Akira ransomware attack.
Read the full story at huntress.com

Sentinel — Human

Confidence

The text reads like an account of a detailed, evidence-based investigation by security researchers, supported by specific artifact references, lending it a high probability of human authorship.

Signals Detected
low severity: Moderate sentence length variance; use of technical jargon interspersed with narrative flow.
low severity: Strong, focused exposition of a complex investigative process. The structure flows logically from setup to findings to remediation.
low severity: Specific artifact linkage (Shellbags, Akira logs, PowerShell commands) suggests grounding in real-world forensic methodology rather than generic claims.
low severity: The text relies heavily on referencing specific artifacts and tool usage; the narrative style is typical of technical reporting, not pure LLM abstraction.
Human Indicators
Use of specialized, context-specific terminology (e.g., Huntress agent, Akira ransomware, Shellbags, C2 tunneling) suggests domain expertise.
The weaving together of specific technical artifacts (Registry data, log files, command lines) into a narrative arc is characteristic of human forensic reporting.
| Huntaegis