Mapping an Akira Ransomware Attack
Score: 7/10

Mapping an Akira Ransomware Attack

Akira ransomware affiliates utilize RDP for initial access, ProcDump for credential theft, and GOST tunnels for persistence before deploying Rclone for exfiltration and encrypting data.

Executive Summary

Huntress researchers analyzed an Akira ransomware incident where the threat actor gained initial access via Remote Desktop Protocol (RDP) from an external workstation. The attacker effectively blinded local defenses by stopping multiple Bitdefender security services before engaging in credential theft and lateral movement. This analysis highlights the importance of monitoring for dual-use tools and defense evasion techniques frequently employed by ransomware affiliates.

The attack chain involved the deployment of the GOST (Go Simple Tunnel) networking tool for persistence and Rclone for cloud-based data exfiltration. While specific attribution was not confirmed for this case, similar tradecraft using GOST has been linked to the China-nexus actor UNC5330. The final stage involved the Akira ransomware binary executing alongside PowerShell commands to delete volume shadow copies, followed by manual verification of encrypted folders via Windows Explorer.

This incident underscores the critical risk of exposed RDP without multi-factor authentication and the necessity of monitoring common staging directories like C:\PerfLogs for unauthorized executable activity.

Key Details

Threat Name

Akira Ransomware

Affects

Wing FTP Server

Adversary

UNC5330 Other Adversaries and Aliases: cl0p

Malware/Tools

Akira, GOST, Rclone

Report Score

7out of 10
Quality Score
Good
IOC Quality8
TTP Details7
Detection Guidance6
Enterprise Relevance9
Clarity & Structure8
Technical Depth7

Sources