Akira Ransomware Campaign Utilizing RDP and GOST Tunneling
The Akira ransomware group utilized RDP for initial access, disabled Bitdefender security services, performed credential dumping with procdump.exe, and deployed GOST tunnels for persistence before executing final file encryption.
In September 2026, an organization was targeted by the Akira ransomware group. Investigations by Huntress, conducted after agent deployment, revealed that the threat actors gained initial access via Remote Desktop Protocol (RDP) from an unauthorized workstation. Upon entry, the attackers systematically disabled Bitdefender antivirus services to facilitate further movement. The threat actors subsequently used procdump.exe from the 'C:\PerfLogs' directory to perform credential theft by dumping the 'lsass.exe' process memory. Data exfiltration was conducted using Rclone, and persistence was established approximately four hours after the start of encryption activities using a GOST (Go Simple Tunnel) tool. The final stage involved encrypting files across the environment and using PowerShell to delete volume shadow copies.
Attack Chain
- The attacker gained initial access to the network via Remote Desktop Protocol (RDP) using credentials from an external, unauthorized workstation.
- The attacker accessed the Bitdefender management console and proceeded to manually stop multiple endpoint protection services, including the 'Bitdefender Endpoint Security Service'.
- The threat actor executed 'procdump.exe' from the 'C:\PerfLogs' folder to dump the 'lsass.exe' memory process to harvest credentials.
- 'Rclone' was deployed and executed to facilitate the exfiltration of sensitive organizational data to attacker-controlled infrastructure.
- The attacker utilized PowerShell to execute commands designed to remove all volume shadow copies from the endpoint, hindering recovery.
- A GOST (Go Simple Tunnel) tool was deployed to establish a persistent network tunnel for continued access.
- The Akira ransomware payload was executed, utilizing 'config.dll' loaded by 'svchost.exe' to initiate the mass encryption of files.
Impact
The attack resulted in the successful encryption of organizational files and the potential exfiltration of sensitive data. Successful Akira operations typically lead to significant operational downtime, financial extortion demands, and data breach notification requirements.
Recommendation
- Enable and monitor Windows Event Log 7036 to detect when security services (e.g., Bitdefender) are stopped unexpectedly.
- Implement strict geofencing and multi-factor authentication (MFA) for all RDP access to prevent unauthorized initial access.
- Monitor for the execution of 'procdump.exe' and similar administrative tools (e.g., comsvcs.dll via rundll32) when initiated by non-administrative users or from suspicious paths like 'C:\PerfLogs'.
- Deploy and enforce EDR rules to block or alert on the execution of 'Rclone' and known tunneling tools like GOST in production environments.
- Restrict the ability of users and processes to modify volume shadow copies via PowerShell or 'vssadmin.exe'.
Immediate actions
Review RDP access logs for unauthorized workstation usage
Threat Hunt
Search for procdump.exe execution in C:\PerfLogs
Data: Process creation logs
Mitigations
Disable RDP for external facing hosts and enforce MFA
Initial Access T1133
Detection coverage 1
Detect Suspicious Service Control Manager Termination
highDetects when Bitdefender security services are manually stopped, which is a common defense evasion technique used by Akira ransomware.
Detection queries are available on the platform. Get full rules →