HomeRisk ManagementsAkira Affiliate Disrupted Ransomware Operation Following EDR Evasion Attempt

Akira Affiliate Disrupted Ransomware Operation Following EDR Evasion Attempt

Published on

spot_img

A recent investigation by Huntress has spotlighted a fascinating misstep made by a ransomware affiliate during a cyber attack. The affiliate, associated with the notorious Akira ransomware group, attempted to disable security mechanisms by rebooting a victim’s system into Safe Mode. However, this tactic backfired and ultimately thwarted the encryption of the target’s files, illustrating the complexities and unpredictable nature of ransomware operations.

In a blog post dated August 12, Huntress detailed how the Akira affiliate first gained access to its victim’s network in early August through a credential spraying attack. This attack exploited vulnerabilities in a SonicWall SSL VPN, which notably lacked multifactor authentication (MFA), a critical layer of security that could have mitigated such an intrusion. Once inside the system, the attacker leveraged Remote Desktop Protocol (RDP) to access the domain controller, initiating a process of Active Directory (AD) enumeration—a common tactic used in Akira attacks, as indicated by Huntress.

After successfully accessing the application server, the attacker proceeded to gather sensitive files, subsequently transferring them to cloud storage using s5cmd, a utility that facilitates quick transfers to Amazon S3 storage solutions. Huntress highlighted that this operational approach exemplifies “classic double extortion,” a strategy wherein attackers not only encrypt the victim’s data but also threaten to publish it on an underground forum or darknet site if the ransom is not paid, thereby maximizing their leverage.

Nevertheless, the attack took an unexpected turn when the threat actor decided to deploy the ransomware payload. Prior to activating the malware, they executed MSConfig.exe to reboot the system into “Safe Mode with Networking.” This mode, typically used for troubleshooting purposes, disables many third-party services, including security tools like the Huntress agent and real-time protection from antivirus software. “For the entire Safe Mode window, the host had no working EDR, and AV was blinded,” Huntress noted, emphasizing the typical intention behind such maneuvers. This approach has been previously documented by MITRE ATT&CK as “Impair Defenses: Safe Mode Boot,” although it had not been specifically associated with Akira previously. Historically, this technique has been the hallmark of other ransomware groups such as Snatch and AvosLocker for years.

However, in a dramatic twist, this maneuver inadvertently hampered the attackers rather than facilitating their objectives. The booting into Safe Mode triggered host memory errors that prevented the ransomware from executing its intended encryption operations. Huntress explained that the stripped-down environment of Safe Mode, with its limited virtual memory, caused the Akira process tree to starve, resulting in an “Out of Virtual Memory” message. This incident coincided with the moment the ransomware attempted to launch, leading to a cascade of errors in PowerShell.

The implications of this incident are noteworthy. Huntress clarified that although Safe Mode successfully blinded the controls, it paradoxically may have prevented the encryption that the attackers sought to initiate. “That’s a lucky side effect of the attacker’s own mistake in these circumstances, not a defense you can plan around,” they explained, underscoring the unpredictable nature of cybersecurity incidents.

Looking forward, Huntress cautioned that future victims of Akira might not be as fortunate. They emphasized that while this specific attack was thwarted, the same scenario could yield different results under different conditions. For instance, a system with more physical memory might provide enough virtual memory for the Akira ransomware to execute successfully even in Safe Mode. The developers behind Akira could also modify the ransomware to reduce its memory requirements or improve its reliability in Safe Mode, potentially leading to successful intrusions in the future.

In light of these developments, organizations are urged to adopt robust preventive measures to safeguard against similar attacks. Huntress recommends several strategies, including:

– Blocking credential spray attacks by monitoring for bursts of failed VPN logins from single sources.
– Establishing a correlation between failed attempts and subsequent successful logins from the same IP or Autonomous System Number (ASN).
– Implementing MFA for every VPN account while disabling or allowing specific IPs for SSL VPNs during potential attacks.
– Rotating all Active Directory (AD) and VPN credentials if a breach is detected.
– Utilizing Endpoint Detection and Response (EDR) on all hosts, as initial preparations for attacks often occur on unmonitored systems.
– Deploying a Security Information and Event Management (SIEM) system to ingest VPN and Windows Event Logs for early warning signs of impending ransomware attacks.
– Monitoring for Safe Mode manipulations—including boot configurations and registry changes—indicative of an ongoing ransomware effort.

By adopting such forward-thinking security measures, organizations can bolster their defenses against the ever-evolving tactics employed by ransomware groups like Akira and prevent falling victim to future attacks.

Source link

Latest articles

AI Agents Launch Near-Autonomous Cyberattack on Asian Government Networks

New Phase in Cybersecurity: Autonomous AI Agents Breach Taiwanese Government Systems In a significant development...

Uncle Sam Calls on Private Hackers to Disrupt Criminal Networks

White House Launches Program to Engage Private Sector in Cyber Surveillance and Operations In a...

Microsoft Exchange Server Vulnerabilities Enable DoS, Privilege Escalation, and Remote Code Execution

Microsoft has recently announced critical security updates aimed at addressing six distinct vulnerabilities found...

Researcher Bypasses Microsoft Defender Patch to Seize Control

Urgent Cybersecurity Alert: New Exploit Threatens System Integrity Through Antivirus Software In a recent security...

More like this

AI Agents Launch Near-Autonomous Cyberattack on Asian Government Networks

New Phase in Cybersecurity: Autonomous AI Agents Breach Taiwanese Government Systems In a significant development...

Uncle Sam Calls on Private Hackers to Disrupt Criminal Networks

White House Launches Program to Engage Private Sector in Cyber Surveillance and Operations In a...

Microsoft Exchange Server Vulnerabilities Enable DoS, Privilege Escalation, and Remote Code Execution

Microsoft has recently announced critical security updates aimed at addressing six distinct vulnerabilities found...