← All hunts critical TLP:CLEAR Part 3 of 3

Akira Ransomware Exfiltration and Impact

An adversary is exfiltrating bulk data via SFTP using FileZilla and executing Akira ransomware, evidenced by massive outbound network transfers and the destruction of Volume Shadow Copies.

Based on research by The DFIR Report 2026-09-29 9 steps · 3 queries T1020 T1047 T1048.003 T1486 T1490

Brief

The DFIR Report recently published "From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira" (https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/), detailing an intrusion that moves from initial access to full-scale ransomware deployment. This hunt focuses on the final, high-impact phase: data exfiltration and system impact. By the time an adversary reaches this stage, they have already established persistence and moved laterally. Detecting these terminal actions provides the last opportunity for intervention before catastrophic data loss. This hunt addresses several MITRE ATT&CK techniques, including T1048.003 (Exfiltration over Uncommonly Used Port), T1020 (Automated Exfiltration), T1486 (Data Encrypted for Impact), T1490 (Inhibit System Recovery), and T1047 (Windows Management Instrumentation).

How the Hunt Flows

The hunt starts with scoping on the hb_process_activity surface. It searches for the execution of known exfiltration tools and the ransomware binary itself. The query checks the original file name field to find tools like filezilla.exe or sftp.exe even if the adversary renames them to look like legitimate system utilities. It also targets the primary Akira payload, often named locker.exe. If these binaries appear on any host, especially critical servers like domain controllers or file shares, the hunt proceeds to behavioral corroboration. Next, the hunt examines hb_network_connection to identify bulk data movement. The logic stacks outbound connections by destination IP and port, filtering for traffic volumes exceeding 100MB. It looks for destinations that appear on only one or two hosts in the environment. This helps distinguish targeted data exfiltration to a unique adversary-controlled server from routine, environment-wide backup processes. The report observed massive transfers to IPs in the Ukraine IP space, which this stacking query would highlight as a high-confidence outlier. Simultaneously, the hunt monitors for the deletion of Volume Shadow Copies on the hb_process_activity surface. It looks for the use of vssadmin.exe, wmic.exe, or PowerShell to execute "shadow" and "delete" commands. Adversaries use these commands to prevent victims from recovering their data using built-in Windows features. Because legitimate backup software also interacts with shadow copies, the hunt specifically searches for the "delete" verb in the command line, which is a rare action for standard maintenance. Finally, the hunt uses an agent to triage these signals. The agent reviews the tool execution, the network outliers, and the impact commands to provide a per-host verdict. If a host shows both the presence of exfiltration tools and the deletion of shadows, the hunt triggers an immediate isolation action. This coordinated approach allows defenders to act with confidence, knowing the signals represent a synchronized malicious effort rather than isolated administrative tasks.

Blind Spots

This hunt has two primary blind spots. First, it relies on traffic_bytes counters in network logs. If the logging solution only records connection events without flow volume, the hunt identifies the rare destination but cannot confirm the 75GB exfiltration reported in the source. Second, if the ransomware uses direct API calls to the Volume Shadow Copy Service instead of command-line tools, the process monitoring surface will miss the impact phase.

In this series

Steps

  1. Identify Suspect Processes

    Query · scoping

    Locate execution of the reported exfiltration tools or ransomware binaries by matching original file names to bypass renaming evasion.

    reads hb_process_activitysql
    SELECT device_hostname, process_name, process_original_file_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{exfil_tools}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0 OR instr(',' || '{{ransomware_binaries}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. A hit names the host and binary (e.g., locker.exe renamed or FileZilla). Silence suggests these specific binaries did not run in the lookback window.

  2. Bulk Exfiltration Stacking

    Query · baseline

    Identify hosts pushing massive outbound volume (over 100MB) to destinations seen on very few hosts, characteristic of data theft.

    reads hb_network_connectionsql
    SELECT dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS host_count, SUM(traffic_bytes) AS total_bytes, MIN(time) AS first_seen FROM hb_network_connection WHERE state_kind = 'log' AND traffic_bytes > 104857600 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip, dst_endpoint_port HAVING host_count < 3 ORDER BY total_bytes DESC

    What a hit looks like. One or two hosts pushing huge volume to a unique IP, especially on port 22 (SFTP). Benign noise includes backup servers; outliers represent potential exfiltration.

  3. Shadow Copy Removal

    Query · detection candidate

    Detect the final precursor to ransomware impact: the deletion of Volume Shadow Copies using administrative tools.

    reads hb_process_activitysql
    SELECT device_hostname, process_name, process_cmd_line, time FROM hb_process_activity WHERE (instr(',' || '{{impact_admin_tools}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{impact_admin_tools}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND LOWER(process_cmd_line) LIKE '%shadow%' AND LOWER(process_cmd_line) LIKE '%delete%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Process rows showing tools like vssadmin or wmic used to delete shadows. This is a high-confidence indicator of ransomware preparation.

  4. Triage Final Stage

    Agent triage

    Synthesize tool execution, bulk network flow, and backup destruction into a single maliciousness verdict per host.

  5. Route Remediation

    Decision

    Direct the response based on the agent's triage results.

  6. Isolate Affected Host

    Response action

    Prevent the spread of encryption and stop ongoing data exfiltration.

  7. Analyst Impact Review

    Analyst task

    Confirm the scope of data theft and the progress of encryption.

  8. Hunt Close-out

    Analyst task

    Document findings and transition to incident response if required.

Coverage

Scenario coverage

StageCoveredHow, or why not
Data Exfiltration via SFTP
T1048.003 · T1020
Yes identify-suspect-processes, bulk-exfiltration-stacking
Akira Ransomware Impact
T1486 · T1490 · T1047
Yes identify-suspect-processes, shadow-copy-removal
SEO Poisoning Redirection
T1189 · T1583.008
Out of scope Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.
Bumblebee DLL Side-Loading
T1204.002 · T1574.002
Out of scope Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.
AdaptixC2 Infrastructure Setup
T1071.001 · T1568.002 · T1055
Out of scope Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.
Internal Reconnaissance and Persistence
T1082 · T1016 · T1136.002 · T1543.003
Out of scope Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.
SSH Tunneling and RDP Pivot
T1021.001 · T1572
Out of scope Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.
Active Directory and Veeam Credential Harvesting
T1003.003 · T1003.001 · T1552.004
Out of scope Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.

Blind spots

  • Needs hb_network_connection with traffic_bytes from flow logs. Without byte counters, we can see the connection to the Ukrainian destination but cannot confirm the magnitude of the data breach. It would answer Was 75GB of data actually exfiltrated?.
  • Needs Endpoint monitoring for COM/WMI API calls. Advanced ransomware using direct API calls (e.g., IVssBackupComponents) to delete shadows will bypass process command-line monitoring. It would answer Was shadow deletion performed without using the command line?.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
exfil_toolslist[string]filezilla.exe, sftp.exeOriginal file names of common exfiltration tools.
impact_admin_toolslist[string]vssadmin.exe, wmic.exe, powershell.exe, pwsh.exe, powershell_ise.exeLegitimate administrative tools often abused for shadow copy deletion.
lookback_daysnumber14Days of history to examine.
ransomware_binarieslist[string]locker.exe, akira.exeOriginal file names associated with the Akira payload.
scope_hostslist[host]—Limit the hunt to specific hosts; leave empty to scan the full estate.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Network telemetrynetworknetwork

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A single rule might alert on vssadmin usage, but this hunt pivots between
  original binary names, rare destination stacking, and network volume across three
  different telemetry surfaces to distinguish a ransomware incident from administrative
  maintenance.
blind_spots:
- id: missing-byte-counters
  question: Was 75GB of data actually exfiltrated?
  requires: hb_network_connection with traffic_bytes from flow logs
  risk: Without byte counters, we can see the connection to the Ukrainian destination
    but cannot confirm the magnitude of the data breach.
  stage: data-exfiltration-sftp
- id: api-shadow-deletion
  question: Was shadow deletion performed without using the command line?
  requires: Endpoint monitoring for COM/WMI API calls
  risk: Advanced ransomware using direct API calls (e.g., IVssBackupComponents) to
    delete shadows will bypass process command-line monitoring.
  stage: impact-ransomware-encryption
coverage:
- stage: data-exfiltration-sftp
  status: covered
  steps:
  - identify-suspect-processes
  - bulk-exfiltration-stacking
- stage: impact-ransomware-encryption
  status: covered
  steps:
  - identify-suspect-processes
  - shadow-copy-removal
- reason: 'Belongs to another part of the ''From Bing Search to Ransomware: Bumblebee
    and AdaptixC2 Deliver Akira'' series.'
  stage: initial-access-seo-redirection
  status: out_of_scope
- reason: 'Belongs to another part of the ''From Bing Search to Ransomware: Bumblebee
    and AdaptixC2 Deliver Akira'' series.'
  stage: execution-dll-side-loading
  status: out_of_scope
- reason: 'Belongs to another part of the ''From Bing Search to Ransomware: Bumblebee
    and AdaptixC2 Deliver Akira'' series.'
  stage: c2-establishment-adaptix
  status: out_of_scope
- reason: 'Belongs to another part of the ''From Bing Search to Ransomware: Bumblebee
    and AdaptixC2 Deliver Akira'' series.'
  stage: internal-discovery-and-persistence
  status: out_of_scope
- reason: 'Belongs to another part of the ''From Bing Search to Ransomware: Bumblebee
    and AdaptixC2 Deliver Akira'' series.'
  stage: lateral-movement-tunneling
  status: out_of_scope
- reason: 'Belongs to another part of the ''From Bing Search to Ransomware: Bumblebee
    and AdaptixC2 Deliver Akira'' series.'
  stage: credential-access-harvesting
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: Akira ransomware results in total business disruption; detecting
    the terminal exfiltration phase and backup destruction provides the final opportunity
    for intervention before catastrophic data loss.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary is exfiltrating bulk data via SFTP using FileZilla and executing
  Akira ransomware, evidenced by massive outbound network transfers and the destruction
  of Volume Shadow Copies.
labels:
- hunt
- attack.t1048.003
- attack.t1020
- attack.t1486
- attack.t1490
- attack.t1047
- command and control
- credential access
- discovery
- execution
- exfiltration
- impact
- initial access
- lateral movement
name: Akira Ransomware Exfiltration and Impact
parameters:
  exfil_tools:
    default:
    - filezilla.exe
    - sftp.exe
    description: Original file names of common exfiltration tools.
    from:
      kind: article
      observed: '2025-07-01'
      ref: dfir-report-akira
    type: list[string]
  impact_admin_tools:
    default:
    - vssadmin.exe
    - wmic.exe
    - powershell.exe
    - pwsh.exe
    - powershell_ise.exe
    description: Legitimate administrative tools often abused for shadow copy deletion.
    from:
      kind: article
      observed: '2025-07-01'
      ref: dfir-report-akira
    type: list[string]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  ransomware_binaries:
    default:
    - locker.exe
    - akira.exe
    description: Original file names associated with the Akira payload.
    from:
      kind: article
      observed: '2025-07-01'
      ref: dfir-report-akira
    type: list[string]
  scope_hosts:
    default: []
    description: Limit the hunt to specific hosts; leave empty to scan the full estate.
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Focus the hunt on file servers, domain controllers, and backup infrastructure
  (e.g., Veeam servers), as these were specifically targeted for bulk data theft and
  encryption in this scenario.
references:
- name: "The DFIR Report \u2014 From Bing Search to Ransomware: Bumblebee and AdaptixC2\
    \ Deliver Akira"
  url: https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/
related:
- hunt: bumblebee-loader-behavior
  reason: The initial delivery and C2 establishment phases are handled in the first
    hunt of this series.
  relation: out-of-scope-alternative
- hunt: bumblebee-persistence-and-ad-credential-harvesting
  relation: follows
scenario:
  stages:
  - name: SEO Poisoning Redirection
    observables:
    - opmanager.pro
    - download-center.online
    - ip-scanner.org
    - download-server.online
    - soft-server.online
    - soft-hub.pro
    - netml.shop
    - /Get?q=
    slug: initial-access-seo-redirection
    tactic: initial-access
    techniques:
    - T1189
    - T1583.008
  - name: Bumblebee DLL Side-Loading
    observables:
    - ManageEngine-OpManager.msi
    - consent.exe
    - msimg32.dll
    - '%TEMP%\ApplicationInstallationFolder_11'
    - ApplicationInstallationFolder_11
    slug: execution-dll-side-loading
    tactic: execution
    techniques:
    - T1204.002
    - T1574.002
  - name: AdaptixC2 Infrastructure Setup
    observables:
    - AdgNsy.exe
    - 4.239.95.1:8080
    - 84.32.84.32
    slug: c2-establishment-adaptix
    tactic: command-and-control
    techniques:
    - T1071.001
    - T1568.002
    - T1055
  - name: Internal Reconnaissance and Persistence
    observables:
    - systeminfo
    - nltest
    - RustDesk
    - Enterprise Admin accounts
    slug: internal-discovery-and-persistence
    tactic: discovery
    techniques:
    - T1082
    - T1016
    - T1136.002
    - T1543.003
  - name: SSH Tunneling and RDP Pivot
    observables:
    - reverse SSH tunnel
    - RDP proxy traffic
    slug: lateral-movement-tunneling
    tactic: lateral-movement
    techniques:
    - T1021.001
    - T1572
  - name: Active Directory and Veeam Credential Harvesting
    observables:
    - wbadmin.exe
    - ntds.dit
    - lsassy
    - Veeam credential dumping script
    slug: credential-access-harvesting
    tactic: credential-access
    techniques:
    - T1003.003
    - T1003.001
    - T1552.004
  - name: Data Exfiltration via SFTP
    observables:
    - FileZilla.exe
    - 75GB exfiltrated
    - Ukrainian IP space
    slug: data-exfiltration-sftp
    tactic: exfiltration
    techniques:
    - T1048.003
    - T1020
  - name: Akira Ransomware Impact
    observables:
    - locker.exe
    - delete Volume Shadow Copies
    - WMI
    slug: impact-ransomware-encryption
    tactic: impact
    techniques:
    - T1486
    - T1490
    - T1047
  summary: Threat actors utilized Bing SEO poisoning to deliver Bumblebee malware
    via trojanized software installers, leading to the deployment of AdaptixC2 for
    network discovery. The attackers leveraged RDP over SSH tunnels to move laterally
    and harvest credentials from NTDS.dit and LSASS before exfiltrating 75GB of data
    and deploying Akira ransomware.
series:
  index: 3
  slug: from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira
  title: 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira'
  total: 3
severity: critical
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  network:
    category: network
    name: Network telemetry
    telemetry:
    - network
tlp: clear
type: investigation
---


# Akira Ransomware Exfiltration and Impact

This hunt identifies the final, high-impact phase of an Akira ransomware intrusion. It scopes for the execution of known exfiltration tools and the ransomware binary itself (locker.exe), then corroborates this with behavioral evidence: bulk network transfers to rare destinations—matching the 75GB volume reported—and the deletion of system recovery options via shadow copy removal. An agent triages these signals to confirm if a host has reached the final stage of encryption, enabling immediate containment before widespread business disruption occurs.

## identify-suspect-processes
<!-- Identify Suspect Processes -->
Locate execution of the reported exfiltration tools or ransomware binaries by matching original file names to bypass renaming evasion.

```sqlite target=endpoint role=scoping params=(exfil_tools=exfil_tools, ransomware_binaries=ransomware_binaries, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: A hit names the host and binary (e.g., locker.exe renamed or FileZilla).
  Silence suggests these specific binaries did not run in the lookback window.
reads:
- device_hostname
- process_name
- process_original_file_name
- process_cmd_line
- user_name
- time
silence: evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, process_name, process_original_file_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{exfil_tools}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0 OR instr(',' || '{{ransomware_binaries}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## parallel-corroboration
<!-- Corroborate Exfiltration and Impact -->
parallel:
- → bulk-exfiltration-stacking
- → shadow-copy-removal
join: → triage-final-stage

## bulk-exfiltration-stacking
<!-- Bulk Exfiltration Stacking -->
Identify hosts pushing massive outbound volume (over 100MB) to destinations seen on very few hosts, characteristic of data theft.

```sqlite target=network role=baseline params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: One or two hosts pushing huge volume to a unique IP, especially on port
  22 (SFTP). Benign noise includes backup servers; outliers represent potential exfiltration.
prevalence:
  by: device_hostname
  key:
  - dst_endpoint_ip
  rare_below: 3
reads:
- dst_endpoint_ip
- dst_endpoint_port
- device_hostname
- traffic_bytes
- time
- state_kind
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS host_count, SUM(traffic_bytes) AS total_bytes, MIN(time) AS first_seen FROM hb_network_connection WHERE state_kind = 'log' AND traffic_bytes > 104857600 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip, dst_endpoint_port HAVING host_count < 3 ORDER BY total_bytes DESC
```

## shadow-copy-removal
<!-- Shadow Copy Removal -->
Detect the final precursor to ransomware impact: the deletion of Volume Shadow Copies using administrative tools.

```sqlite target=endpoint role=detection-candidate params=(impact_admin_tools=impact_admin_tools, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Process rows showing tools like vssadmin or wmic used to delete shadows.
  This is a high-confidence indicator of ransomware preparation.
reads:
- device_hostname
- process_name
- process_cmd_line
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, process_name, process_cmd_line, time FROM hb_process_activity WHERE (instr(',' || '{{impact_admin_tools}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{impact_admin_tools}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND LOWER(process_cmd_line) LIKE '%shadow%' AND LOWER(process_cmd_line) LIKE '%delete%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## triage-final-stage
<!-- Triage Final Stage -->
```agent target=hunter
cite: required
context:
- identify-suspect-processes
- bulk-exfiltration-stacking
- shadow-copy-removal
max_iterations: 4
objective: Determine if the presence of suspect binaries (FileZilla/locker.exe), bulk
  outbound transfers, and shadow deletion together indicate an active ransomware intrusion.
success_criteria: A per-host verdict citing specific rows from process and network
  surfaces.
tools:
- endpoint
- network
```

## route-remediation
<!-- Route Remediation -->
if~: "the triage verdict is malicious for at least one host based on correlated exfiltration and impact signals" (confidence: high, judge=hunter)
then: → isolate-affected-host
indeterminate: → analyst-impact-review
unavailable: → analyst-impact-review (blind_spot: missing-byte-counters)
else: → close-out-hunt

## isolate-affected-host
<!-- Isolate Affected Host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host immediately. Revoke all active sessions for users observed executing exfiltration tools or the ransomware binary.
```
→ analyst-impact-review

## analyst-impact-review
<!-- Analyst Impact Review -->
```manual target=analyst
Verify the destination IP in the Ukraine IP space; check the host for the .akira extension on critical file shares and backup drives.
```
→ close-out-hunt

## close-out-hunt
<!-- Hunt Close-out -->
```manual target=analyst
Record the total bytes exfiltrated per host. If no activity was found, ensure the exfiltration tools are included in software restriction policies.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.