
Huntress Reconstructs Akira Ransomware Attack From Registry Artifacts After Post-Compromise EDR Install
Huntress shows how Shellbags, Akira logs, and PowerShell shadow-copy toolmarks reconstructed an Akira intrusion after a post-compromise agent install left only a thin EDR slice of GOST tunneling and related activity.
Noah Park, ResponseNew York5 min read
NEW YORK - In September, Huntress deployed its agent on an organization already hit by Akira ransomware. The post-compromise install left a thin slice of EDR telemetry, so researchers reconstructed the intrusion from Windows Registry artifacts, Akira log files, Windows Event Logs, and PowerShell records. In an Oct. 6 report, Harlan Carvey and Lindsey O'Donnell-Welch show how those "toolmark" traces still mapped RDP access, antivirus shutdown, credential dumping, a GOST tunnel, Rclone exfiltration, and encryption of Shares folders, even without a captured ransomware command line.
After the agent landed in early September, an Expedited High signal on a domain controller caught svchost.exe running from C:\PerfLogs\Temp\ under SYSTEM and loading config.dll. That alert was only the tip of activity still visible after install. Event logs showed Terminal Services/RDP from a workstation the customer did not own. Shortly afterward, several Bitdefender endpoint services were stopped, and procdump.exe ran from C:\PerfLogs, consistent with dumping lsass.exe. About four hours after encryption began, the actor launched a GOST (Go Simple Tunnel) binary masquerading as svchost.exe from the same PerfLogs Temp path, with config.dll pointing traffic through an SSH forward to 64.227.4[.]134 on port 443. VirusTotal flagged that GOST hash as gost-windows-amd64.exe. Rclone then ran from C:\PerfLogs for cloud sync exfiltration.


Without full process telemetry for the encryptor, analysts leaned on Shellbags, Akira logs, and PowerShell. Shellbags showed the actor browsing Shares subfolders before the first Akira run. A PowerShell command removing volume shadow copies via Win32_Shadowcopy lined up with creation of an Akira log targeting Shares. Within a minute, Shellbags showed Explorer checks of encrypted subfolders. That launch-log-verify loop repeated three more times. Huntress lists IOCs including threat-actor workstation C1IFRYXI, GOST C2 64.227.4[.]134, ransomware SHA256 1f1bb322591b6d27fd2946e373d7d2efc2f4e1e66818846060d391600b600fba at C:\storage\win.exe, and GOST SHA256 d00833318a04caa019c6f95dcb3598ad947d405010bfb2f3cbd04530a00bc3a4 at C:\PerfLogs\temp\svchost.exe.

For SOC and IR teams, the case is a reminder that late EDR coverage does not end the investigation. Monitor unknown RDP source workstations, watch C:\PerfLogs for unexpected binaries, and treat Shellbags, ransomware log files, and shadow-copy removal PowerShell as first-class evidence when agent telemetry starts mid-incident. Huntress also notes MFA on exposed remote access, asset inventory, and attack-surface reduction as practical mitigations.
Sources:
Noah Park covers incident response and blue-team operations for SOCtember from New York.
Related stories
Response
Huntress Sees Active Exploitation of AhsayCBS Backup Flaws Dropping Webshells and XMRig Across Five Organizations
Response
FBI and Secret Service Warn FortiBleed Hackers Are Locking Some Fortinet Customers Out of Their Own Firewalls
Response
CISA Flags TeamCity Flaw CVE-2026-63077 as Used in Ransomware Campaigns
Detection