BushidoUK ToolMatrix CommunityReports: CR-010-AKIRA-AUG-2025

Fecha
18 Jun 2026
Actor
bushidouk
Tipo
Report
Pais
United States
Sector
Defense
Confianza
high
100
Prioridad analitica
Alta

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

10IOCs
0TTPs
bushidoukActor
United StatesPais
Executive Summary
Recurso del BushidoUK Ransomware Tool Matrix - CommunityReports.

Key Points

  • Source: CommunityReports/CR-010-AKIRA-AUG-2025.md
  • BushidoUK Tool Matrix

CommunityReports: CR-010-AKIRA-AUG-2025.md

Recurso del BushidoUK Ransomware Tool Matrix - CommunityReports.

Community Report 010 - Akira August 2025

Contributor Details

``

- Real Name: Ben Folland

- Online Handle: @polygonben

- Employer: Huntress

`

---

Adversary

`

- Named adversary: Akira

`

---

Incident Details

`

- Time of Incident: August 2025

- Victim Sector: Engineering

- Victim Country: USA

- Victom Size: 1-100

`

---

Observed Tools

| Discovery | RMM Tools | Defense Evasion | Credential Theft | OffSec | Networking | LOLBAS | Exfiltration |

|---|---|---|---|---|---|---|---|

| Advanced IP Scanner | | | | | Cloudflared | vssadmin | WinRAR |

| | | | | | OpenSSH | netsh | FileZilla |

---

Indicators of Compromise (IOCs)

`

Process Chain / Command Lines:

- powershell.exe -Command "Get-WmiObject Win32_Shadowcopy | Remove-WmiObject"

- "C:\WINDOWS\system32\netsh.exe" advfirewall set allprofiles state off

- "C:\WINDOWS\system32\vssadmin.exe" delete shadows /all /quiet

- "C:\WINDOWS\system32\NOTEPAD.EXE" C:\ProgramData\shares.txt

- "C:\Program Files\WinRAR\WinRAR.exe" a -ep1 -scul -r0 -iext -imon1 -- . C:\SHARE1 C:\SHARE2 C:\SHARE3

- "C:\Program Files\FileZilla FTP Client\fzsftp.exe" -v

- "C:\WINDOWS\System32\msiexec.exe" /i "C:\Users\[REDACTED]\Desktop\OpenSSHa.msi"

Staging:

- C:\ProgramData\

Ransomware Binary:

- w.exe -p=\\[REDDACTED].local\C$ -n=1

``

---

#### Any Related Sources

| Date Published | Report |

|---|---|

| 04/08/2025 | https://www.huntress.com/blog/exploitation-of-sonicwall-vpn |

Referencias

Diamond Model

Adversary
bushidouk
Ver perfil →
Victim
BushidoUK ToolMatrix CommunityReports: CR-010-AKIRA-AUG-2025
United States
Capability
Report
Infrastructure
www.huntress.com

Relations

Mapa de nodos relacionados por IOCs compartidos, actor, enlaces IntelTracker/OSINT, campanas y victimas observadas. Haz click en un nodo para abrir el post, filtro o fuente.

20 enlaces
Nodo actual
BushidoUK ToolMatrix CommunityReports: CR-010-AKIRA-AUG-2025
bushidouk · United States

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
File powershell.exe Artefacto observado VT OffSec SOCRadar
File netsh.exe Artefacto observado VT OffSec SOCRadar
File vssadmin.exe Artefacto observado VT OffSec SOCRadar
File NOTEPAD.EXE Artefacto observado VT OffSec SOCRadar
File shares.txt Artefacto observado VT OffSec SOCRadar
File WinRAR.exe Artefacto observado VT OffSec SOCRadar
File fzsftp.exe Artefacto observado VT OffSec SOCRadar
File msiexec.exe Artefacto observado VT OffSec SOCRadar
File OpenSSHa.msi Artefacto observado VT OffSec SOCRadar
Domain www.huntress.com Extraido del contenido VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor bushidouk en el blog → Ver bushidouk en IntelTracker → Fuente OSINT: github.com→ Fuente OSINT: github.com → Buscar bushidouk en APTTrail → Repositorio APTTrail → Mas incidentes en United States → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes