Executive Summary
Huntress researchers analyzed an Akira ransomware incident where the threat actor gained initial access via Remote Desktop Protocol (RDP) from an external workstation. The attacker effectively blinded local defenses by stopping multiple Bitdefender security services before engaging in credential theft and lateral movement. This analysis highlights the importance of monitoring for dual-use tools and defense evasion techniques frequently employed by ransomware affiliates.
The attack chain involved the deployment of the GOST (Go Simple Tunnel) networking tool for persistence and Rclone for cloud-based data exfiltration. While specific attribution was not confirmed for this case, similar tradecraft using GOST has been linked to the China-nexus actor UNC5330. The final stage involved the Akira ransomware binary executing alongside PowerShell commands to delete volume shadow copies, followed by manual verification of encrypted folders via Windows Explorer.
This incident underscores the critical risk of exposed RDP without multi-factor authentication and the necessity of monitoring common staging directories like C:\PerfLogs for unauthorized executable activity.
