Akira Ransomware Exfiltration and Impact
An adversary is exfiltrating bulk data via SFTP using FileZilla and executing Akira ransomware, evidenced by massive outbound network transfers and the destruction of Volume Shadow Copies.
Based on research by The DFIR Report 2026-09-29 9 steps · 3 queries T1020 T1047 T1048.003 T1486 T1490
Brief
The DFIR Report recently published "From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira" (https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/), detailing an intrusion that moves from initial access to full-scale ransomware deployment. This hunt focuses on the final, high-impact phase: data exfiltration and system impact. By the time an adversary reaches this stage, they have already established persistence and moved laterally. Detecting these terminal actions provides the last opportunity for intervention before catastrophic data loss. This hunt addresses several MITRE ATT&CK techniques, including T1048.003 (Exfiltration over Uncommonly Used Port), T1020 (Automated Exfiltration), T1486 (Data Encrypted for Impact), T1490 (Inhibit System Recovery), and T1047 (Windows Management Instrumentation).
How the Hunt Flows
The hunt starts with scoping on the hb_process_activity surface. It searches for the execution of known exfiltration tools and the ransomware binary itself. The query checks the original file name field to find tools like filezilla.exe or sftp.exe even if the adversary renames them to look like legitimate system utilities. It also targets the primary Akira payload, often named locker.exe. If these binaries appear on any host, especially critical servers like domain controllers or file shares, the hunt proceeds to behavioral corroboration. Next, the hunt examines hb_network_connection to identify bulk data movement. The logic stacks outbound connections by destination IP and port, filtering for traffic volumes exceeding 100MB. It looks for destinations that appear on only one or two hosts in the environment. This helps distinguish targeted data exfiltration to a unique adversary-controlled server from routine, environment-wide backup processes. The report observed massive transfers to IPs in the Ukraine IP space, which this stacking query would highlight as a high-confidence outlier. Simultaneously, the hunt monitors for the deletion of Volume Shadow Copies on the hb_process_activity surface. It looks for the use of vssadmin.exe, wmic.exe, or PowerShell to execute "shadow" and "delete" commands. Adversaries use these commands to prevent victims from recovering their data using built-in Windows features. Because legitimate backup software also interacts with shadow copies, the hunt specifically searches for the "delete" verb in the command line, which is a rare action for standard maintenance. Finally, the hunt uses an agent to triage these signals. The agent reviews the tool execution, the network outliers, and the impact commands to provide a per-host verdict. If a host shows both the presence of exfiltration tools and the deletion of shadows, the hunt triggers an immediate isolation action. This coordinated approach allows defenders to act with confidence, knowing the signals represent a synchronized malicious effort rather than isolated administrative tasks.
Blind Spots
This hunt has two primary blind spots. First, it relies on traffic_bytes counters in network logs. If the logging solution only records connection events without flow volume, the hunt identifies the rare destination but cannot confirm the 75GB exfiltration reported in the source. Second, if the ransomware uses direct API calls to the Volume Shadow Copy Service instead of command-line tools, the process monitoring surface will miss the impact phase.
In this series
Steps
-
Identify Suspect Processes
Query · scopingLocate execution of the reported exfiltration tools or ransomware binaries by matching original file names to bypass renaming evasion.
reads hb_process_activitysqlSELECT device_hostname, process_name, process_original_file_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{exfil_tools}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0 OR instr(',' || '{{ransomware_binaries}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. A hit names the host and binary (e.g., locker.exe renamed or FileZilla). Silence suggests these specific binaries did not run in the lookback window.
-
Bulk Exfiltration Stacking
Query · baselineIdentify hosts pushing massive outbound volume (over 100MB) to destinations seen on very few hosts, characteristic of data theft.
reads hb_network_connectionsqlSELECT dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS host_count, SUM(traffic_bytes) AS total_bytes, MIN(time) AS first_seen FROM hb_network_connection WHERE state_kind = 'log' AND traffic_bytes > 104857600 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip, dst_endpoint_port HAVING host_count < 3 ORDER BY total_bytes DESCWhat a hit looks like. One or two hosts pushing huge volume to a unique IP, especially on port 22 (SFTP). Benign noise includes backup servers; outliers represent potential exfiltration.
-
Shadow Copy Removal
Query · detection candidateDetect the final precursor to ransomware impact: the deletion of Volume Shadow Copies using administrative tools.
reads hb_process_activitysqlSELECT device_hostname, process_name, process_cmd_line, time FROM hb_process_activity WHERE (instr(',' || '{{impact_admin_tools}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{impact_admin_tools}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND LOWER(process_cmd_line) LIKE '%shadow%' AND LOWER(process_cmd_line) LIKE '%delete%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. Process rows showing tools like vssadmin or wmic used to delete shadows. This is a high-confidence indicator of ransomware preparation.
-
Triage Final Stage
Agent triageSynthesize tool execution, bulk network flow, and backup destruction into a single maliciousness verdict per host.
-
Route Remediation
DecisionDirect the response based on the agent's triage results.
-
Isolate Affected Host
Response actionPrevent the spread of encryption and stop ongoing data exfiltration.
-
Analyst Impact Review
Analyst taskConfirm the scope of data theft and the progress of encryption.
-
Hunt Close-out
Analyst taskDocument findings and transition to incident response if required.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| Data Exfiltration via SFTP T1048.003 · T1020 |
Yes | identify-suspect-processes, bulk-exfiltration-stacking |
| Akira Ransomware Impact T1486 · T1490 · T1047 |
Yes | identify-suspect-processes, shadow-copy-removal |
| SEO Poisoning Redirection T1189 · T1583.008 |
Out of scope | Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series. |
| Bumblebee DLL Side-Loading T1204.002 · T1574.002 |
Out of scope | Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series. |
| AdaptixC2 Infrastructure Setup T1071.001 · T1568.002 · T1055 |
Out of scope | Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series. |
| Internal Reconnaissance and Persistence T1082 · T1016 · T1136.002 · T1543.003 |
Out of scope | Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series. |
| SSH Tunneling and RDP Pivot T1021.001 · T1572 |
Out of scope | Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series. |
| Active Directory and Veeam Credential Harvesting T1003.003 · T1003.001 · T1552.004 |
Out of scope | Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series. |
Blind spots
- Needs hb_network_connection with traffic_bytes from flow logs. Without byte counters, we can see the connection to the Ukrainian destination but cannot confirm the magnitude of the data breach. It would answer Was 75GB of data actually exfiltrated?.
- Needs Endpoint monitoring for COM/WMI API calls. Advanced ransomware using direct API calls (e.g., IVssBackupComponents) to delete shadows will bypass process command-line monitoring. It would answer Was shadow deletion performed without using the command line?.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
exfil_tools | list[string] | filezilla.exe, sftp.exe | Original file names of common exfiltration tools. |
impact_admin_tools | list[string] | vssadmin.exe, wmic.exe, powershell.exe, pwsh.exe, powershell_ise.exe | Legitimate administrative tools often abused for shadow copy deletion. |
lookback_days | number | 14 | Days of history to examine. |
ransomware_binaries | list[string] | locker.exe, akira.exe | Original file names associated with the Akira payload. |
scope_hosts | list[host] | — | Limit the hunt to specific hosts; leave empty to scan the full estate. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
| Network telemetry | network | network |
Source
---
analysis: A single rule might alert on vssadmin usage, but this hunt pivots between
original binary names, rare destination stacking, and network volume across three
different telemetry surfaces to distinguish a ransomware incident from administrative
maintenance.
blind_spots:
- id: missing-byte-counters
question: Was 75GB of data actually exfiltrated?
requires: hb_network_connection with traffic_bytes from flow logs
risk: Without byte counters, we can see the connection to the Ukrainian destination
but cannot confirm the magnitude of the data breach.
stage: data-exfiltration-sftp
- id: api-shadow-deletion
question: Was shadow deletion performed without using the command line?
requires: Endpoint monitoring for COM/WMI API calls
risk: Advanced ransomware using direct API calls (e.g., IVssBackupComponents) to
delete shadows will bypass process command-line monitoring.
stage: impact-ransomware-encryption
coverage:
- stage: data-exfiltration-sftp
status: covered
steps:
- identify-suspect-processes
- bulk-exfiltration-stacking
- stage: impact-ransomware-encryption
status: covered
steps:
- identify-suspect-processes
- shadow-copy-removal
- reason: 'Belongs to another part of the ''From Bing Search to Ransomware: Bumblebee
and AdaptixC2 Deliver Akira'' series.'
stage: initial-access-seo-redirection
status: out_of_scope
- reason: 'Belongs to another part of the ''From Bing Search to Ransomware: Bumblebee
and AdaptixC2 Deliver Akira'' series.'
stage: execution-dll-side-loading
status: out_of_scope
- reason: 'Belongs to another part of the ''From Bing Search to Ransomware: Bumblebee
and AdaptixC2 Deliver Akira'' series.'
stage: c2-establishment-adaptix
status: out_of_scope
- reason: 'Belongs to another part of the ''From Bing Search to Ransomware: Bumblebee
and AdaptixC2 Deliver Akira'' series.'
stage: internal-discovery-and-persistence
status: out_of_scope
- reason: 'Belongs to another part of the ''From Bing Search to Ransomware: Bumblebee
and AdaptixC2 Deliver Akira'' series.'
stage: lateral-movement-tunneling
status: out_of_scope
- reason: 'Belongs to another part of the ''From Bing Search to Ransomware: Bumblebee
and AdaptixC2 Deliver Akira'' series.'
stage: credential-access-harvesting
status: out_of_scope
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: promote-to-detection
justification: Akira ransomware results in total business disruption; detecting
the terminal exfiltration phase and backup destruction provides the final opportunity
for intervention before catastrophic data loss.
methodology: model-assisted
trigger: intel-report
hypothesis: An adversary is exfiltrating bulk data via SFTP using FileZilla and executing
Akira ransomware, evidenced by massive outbound network transfers and the destruction
of Volume Shadow Copies.
labels:
- hunt
- attack.t1048.003
- attack.t1020
- attack.t1486
- attack.t1490
- attack.t1047
- command and control
- credential access
- discovery
- execution
- exfiltration
- impact
- initial access
- lateral movement
name: Akira Ransomware Exfiltration and Impact
parameters:
exfil_tools:
default:
- filezilla.exe
- sftp.exe
description: Original file names of common exfiltration tools.
from:
kind: article
observed: '2025-07-01'
ref: dfir-report-akira
type: list[string]
impact_admin_tools:
default:
- vssadmin.exe
- wmic.exe
- powershell.exe
- pwsh.exe
- powershell_ise.exe
description: Legitimate administrative tools often abused for shadow copy deletion.
from:
kind: article
observed: '2025-07-01'
ref: dfir-report-akira
type: list[string]
lookback_days:
default: '14'
description: Days of history to examine.
type: number
ransomware_binaries:
default:
- locker.exe
- akira.exe
description: Original file names associated with the Akira payload.
from:
kind: article
observed: '2025-07-01'
ref: dfir-report-akira
type: list[string]
scope_hosts:
default: []
description: Limit the hunt to specific hosts; leave empty to scan the full estate.
type: list[host]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/
gates:
- dry-run
- lint
model: hb_google/gemini-3-flash-preview
rationale: Focus the hunt on file servers, domain controllers, and backup infrastructure
(e.g., Veeam servers), as these were specifically targeted for bulk data theft and
encryption in this scenario.
references:
- name: "The DFIR Report \u2014 From Bing Search to Ransomware: Bumblebee and AdaptixC2\
\ Deliver Akira"
url: https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/
related:
- hunt: bumblebee-loader-behavior
reason: The initial delivery and C2 establishment phases are handled in the first
hunt of this series.
relation: out-of-scope-alternative
- hunt: bumblebee-persistence-and-ad-credential-harvesting
relation: follows
scenario:
stages:
- name: SEO Poisoning Redirection
observables:
- opmanager.pro
- download-center.online
- ip-scanner.org
- download-server.online
- soft-server.online
- soft-hub.pro
- netml.shop
- /Get?q=
slug: initial-access-seo-redirection
tactic: initial-access
techniques:
- T1189
- T1583.008
- name: Bumblebee DLL Side-Loading
observables:
- ManageEngine-OpManager.msi
- consent.exe
- msimg32.dll
- '%TEMP%\ApplicationInstallationFolder_11'
- ApplicationInstallationFolder_11
slug: execution-dll-side-loading
tactic: execution
techniques:
- T1204.002
- T1574.002
- name: AdaptixC2 Infrastructure Setup
observables:
- AdgNsy.exe
- 4.239.95.1:8080
- 84.32.84.32
slug: c2-establishment-adaptix
tactic: command-and-control
techniques:
- T1071.001
- T1568.002
- T1055
- name: Internal Reconnaissance and Persistence
observables:
- systeminfo
- nltest
- RustDesk
- Enterprise Admin accounts
slug: internal-discovery-and-persistence
tactic: discovery
techniques:
- T1082
- T1016
- T1136.002
- T1543.003
- name: SSH Tunneling and RDP Pivot
observables:
- reverse SSH tunnel
- RDP proxy traffic
slug: lateral-movement-tunneling
tactic: lateral-movement
techniques:
- T1021.001
- T1572
- name: Active Directory and Veeam Credential Harvesting
observables:
- wbadmin.exe
- ntds.dit
- lsassy
- Veeam credential dumping script
slug: credential-access-harvesting
tactic: credential-access
techniques:
- T1003.003
- T1003.001
- T1552.004
- name: Data Exfiltration via SFTP
observables:
- FileZilla.exe
- 75GB exfiltrated
- Ukrainian IP space
slug: data-exfiltration-sftp
tactic: exfiltration
techniques:
- T1048.003
- T1020
- name: Akira Ransomware Impact
observables:
- locker.exe
- delete Volume Shadow Copies
- WMI
slug: impact-ransomware-encryption
tactic: impact
techniques:
- T1486
- T1490
- T1047
summary: Threat actors utilized Bing SEO poisoning to deliver Bumblebee malware
via trojanized software installers, leading to the deployment of AdaptixC2 for
network discovery. The attackers leveraged RDP over SSH tunnels to move laterally
and harvest credentials from NTDS.dit and LSASS before exfiltrating 75GB of data
and deploying Akira ransomware.
series:
index: 3
slug: from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira
title: 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira'
total: 3
severity: critical
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
network:
category: network
name: Network telemetry
telemetry:
- network
tlp: clear
type: investigation
---
# Akira Ransomware Exfiltration and Impact
This hunt identifies the final, high-impact phase of an Akira ransomware intrusion. It scopes for the execution of known exfiltration tools and the ransomware binary itself (locker.exe), then corroborates this with behavioral evidence: bulk network transfers to rare destinations—matching the 75GB volume reported—and the deletion of system recovery options via shadow copy removal. An agent triages these signals to confirm if a host has reached the final stage of encryption, enabling immediate containment before widespread business disruption occurs.
## identify-suspect-processes
<!-- Identify Suspect Processes -->
Locate execution of the reported exfiltration tools or ransomware binaries by matching original file names to bypass renaming evasion.
```sqlite target=endpoint role=scoping params=(exfil_tools=exfil_tools, ransomware_binaries=ransomware_binaries, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: A hit names the host and binary (e.g., locker.exe renamed or FileZilla).
Silence suggests these specific binaries did not run in the lookback window.
reads:
- device_hostname
- process_name
- process_original_file_name
- process_cmd_line
- user_name
- time
silence: evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, process_name, process_original_file_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{exfil_tools}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0 OR instr(',' || '{{ransomware_binaries}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```
## parallel-corroboration
<!-- Corroborate Exfiltration and Impact -->
parallel:
- → bulk-exfiltration-stacking
- → shadow-copy-removal
join: → triage-final-stage
## bulk-exfiltration-stacking
<!-- Bulk Exfiltration Stacking -->
Identify hosts pushing massive outbound volume (over 100MB) to destinations seen on very few hosts, characteristic of data theft.
```sqlite target=network role=baseline params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: One or two hosts pushing huge volume to a unique IP, especially on port
22 (SFTP). Benign noise includes backup servers; outliers represent potential exfiltration.
prevalence:
by: device_hostname
key:
- dst_endpoint_ip
rare_below: 3
reads:
- dst_endpoint_ip
- dst_endpoint_port
- device_hostname
- traffic_bytes
- time
- state_kind
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS host_count, SUM(traffic_bytes) AS total_bytes, MIN(time) AS first_seen FROM hb_network_connection WHERE state_kind = 'log' AND traffic_bytes > 104857600 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip, dst_endpoint_port HAVING host_count < 3 ORDER BY total_bytes DESC
```
## shadow-copy-removal
<!-- Shadow Copy Removal -->
Detect the final precursor to ransomware impact: the deletion of Volume Shadow Copies using administrative tools.
```sqlite target=endpoint role=detection-candidate params=(impact_admin_tools=impact_admin_tools, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Process rows showing tools like vssadmin or wmic used to delete shadows.
This is a high-confidence indicator of ransomware preparation.
reads:
- device_hostname
- process_name
- process_cmd_line
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, process_name, process_cmd_line, time FROM hb_process_activity WHERE (instr(',' || '{{impact_admin_tools}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{impact_admin_tools}}' || ',', ',' || LOWER(process_original_file_name) || ',') > 0) AND LOWER(process_cmd_line) LIKE '%shadow%' AND LOWER(process_cmd_line) LIKE '%delete%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```
## triage-final-stage
<!-- Triage Final Stage -->
```agent target=hunter
cite: required
context:
- identify-suspect-processes
- bulk-exfiltration-stacking
- shadow-copy-removal
max_iterations: 4
objective: Determine if the presence of suspect binaries (FileZilla/locker.exe), bulk
outbound transfers, and shadow deletion together indicate an active ransomware intrusion.
success_criteria: A per-host verdict citing specific rows from process and network
surfaces.
tools:
- endpoint
- network
```
## route-remediation
<!-- Route Remediation -->
if~: "the triage verdict is malicious for at least one host based on correlated exfiltration and impact signals" (confidence: high, judge=hunter)
then: → isolate-affected-host
indeterminate: → analyst-impact-review
unavailable: → analyst-impact-review (blind_spot: missing-byte-counters)
else: → close-out-hunt
## isolate-affected-host
<!-- Isolate Affected Host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host immediately. Revoke all active sessions for users observed executing exfiltration tools or the ransomware binary.
```
→ analyst-impact-review
## analyst-impact-review
<!-- Analyst Impact Review -->
```manual target=analyst
Verify the destination IP in the Ukraine IP space; check the host for the .akira extension on critical file shares and backup drives.
```
→ close-out-hunt
## close-out-hunt
<!-- Hunt Close-out -->
```manual target=analyst
Record the total bytes exfiltrated per host. If no activity was found, ensure the exfiltration tools are included in software restriction policies.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.