Skip to content
Huntress Analyzes Akira Ransomware Attack After EDR Failure

Huntress Analyzes Akira Ransomware Attack After EDR Failure

First seen 8 Oct 2026, 12:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 13:30 UTC
  • •Huntress reconstructed an Akira ransomware attack without EDR telemetry.
  • •The attack involved RDP access from an external workstation and the use of GOST for tunneling.
  • •Volume shadow copies were deleted to prevent recovery, a common tactic used by Akira.

In September 2026, Huntress deployed its agent at an organization already compromised by Akira ransomware. The post-compromise installation meant crucial EDR telemetry was missing, hindering initial access insights. Researchers reconstructed the attack using Windows Event Logs, Registry artifacts, and Akira log files. The attack began with the execution of svchost.exe from a suspicious directory, followed by unauthorized access via RDP from an external workstation. The attacker accessed the BitDefender console and executed commands to delete volume shadow copies, a typical Akira tactic. The analysis revealed the use of GOST, an open-source tunneling tool, and Rclone for data exfiltration. The ransomware subsequently encrypted the organization's file shares. Huntress emphasized the importance of maintaining accurate system inventories and reducing attack surfaces.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-01
Huntress agent deployed
The Huntress agent was installed at an organization already compromised by Akira ransomware.
Huntress
2026-09-01
First EDR signal detected
An EDR alert indicated svchost.exe was executed from a suspicious directory, marking the attack's activity.
Itsecurityguru
2026-09-01
Ransomware executed
Akira ransomware was executed against the organization's file shares after the attacker accessed the environment.
Itsecurityguru

More articles in this cluster (2)

Following this threat?

Track Akira in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What systems were affected?
The attack targeted an organization using the Huntress agent, which was deployed post-compromise.
How did the attacker gain access?
The attacker accessed the environment via RDP from an external workstation not owned by the victim.
What should organizations do to prevent similar attacks?
Maintain accurate inventories of systems and reduce attack surfaces to limit exposure to threats.