Skip to content
live markets
S&P 5007,785.76▲ 3.21%NASDAQ26,729.16▲ 2.38%DOW53,732.41▲ 2.33%GOLD4,437.30▲ 11.33%WTI82.40▲ 4.37%BRENT88.52▲ 5.09%EUR/USD1.1573▲ 1.66%USD/JPY159.31▼ 1.92%DXY99.64▼ 1.09%BTC$63,106▲ 0.30%ETH$1,884▲ 0.20%SOL$75.27▲ 0.10%TOTAL CRYPTO$2.25T▲ 0.04%
pulseofnations.
UTC --:--NYC --:--LON --:--WAW --:-- telegram ↗ bluesky ↗ Join the wire

Akira Ransomware Uses Safe Mode to Evade Endpoint Defenses

Akira affiliates forced Windows systems into Safe Mode to disable EDR security tools, though the tactic also accidentally disrupted the ransomware’s own encryption.

Partner Surfshark VPN

Akira ransomware affiliates were observed forcing compromised Windows systems into Safe Mode to disable endpoint detection and response (EDR) tools, according to cybersecurity firm Huntress.

In an investigation of an incident that began on August 4, Huntress analysts found that attackers launched a credential-spraying campaign against an exposed SonicWall SSL VPN. Within seven minutes, an attacker successfully authenticated to an account lacking multi-factor authentication (MFA).

From VPN Breach to Domain Controller

Two hours after initial access, the operator moved to the domain controller over RDP and performed extensive Active Directory enumeration. The attacker then pivoted to an application server, archiving mapped file shares with WinRAR before exfiltrating stolen data to an attacker-controlled S3 bucket using the s5cmd tool, establishing the data-theft component of a double-extortion scheme.

AnyDesk remote access software was installed for persistent access and to deliver the Akira ransomware payload. At this stage, the operator used msconfig.exe to force the machine into Safe Mode with Networking enabled, a Windows troubleshooting environment that loads only essential drivers and services.

Double-Edged Tactic

The technique successfully took both Huntress’s agent and Microsoft Defender’s real-time protection offline, giving the attacker a window to operate without endpoint defenses. Anticipating that AnyDesk itself might not be available in Safe Mode, the attackers modified the Safe Boot registry configuration to ensure the remote-access service would start.

However, the tactic proved to be a double-edged sword. Huntress noted that the Safe Mode reboot also disrupted the ransomware’s own encryption process, as many of the services required for file encryption were similarly disabled by the minimal startup configuration.

Huntress said this was the first time it had observed Akira using the Safe Mode technique, though BlackLotus rootkit operators have employed similar methods to bypass Windows security features. The firm urged organizations to enforce MFA on all VPN accounts and limit remote access to only essential personnel.

Sources: CSO Online; Huntress blog; BleepingComputer

React to this dispatch
Share this dispatch Telegram X WhatsApp Report an error

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch State Cyber Threats From North Korea, China, Russia Up 7.5% Read →