
Figure: Huntress, Figure 1, EDR signal for post-compromise GOST svchost.exe loading config.dll, Oct 6, 2026 (fair use).
RESPONSE · NEW YORK
Huntress Reconstructs Akira Ransomware Attack From Registry Artifacts After Post-Compromise EDR Install
Huntress shows how Shellbags, Akira logs, and PowerShell shadow-copy toolmarks reconstructed an Akira intrusion after a post-compromise agent install left only a thin EDR slice of GOST tunneling and related activity.
October 11, 2026
Noah Park, Response, New York



























