HomeCyber BalkansAkira Ransomware Affiliate Resumes Operations in Safe Mode to Evade EDR and...

Akira Ransomware Affiliate Resumes Operations in Safe Mode to Evade EDR and Compromises Its Own Attack

Published on

spot_img

Akira Ransomware’s Intrusion: A Closer Look at a Flawed Tactic

In a recent cybersecurity incident, an affiliate of the Akira ransomware operation adopted an innovative yet ultimately self-defeating strategy to evade endpoint defenses. By rebooting a compromised server into Windows Safe Mode, the attacker sought to disable security measures, including an Endpoint Detection and Response (EDR) agent and Microsoft Defender. Unfortunately for the attackers, this maneuver backfired, as the reduced functionality of Safe Mode caused their ransomware payload to crash before it could even begin encrypting files.

This incident was brought to light in a detailed technical report released by Huntress, a managed detection and response provider. It highlights a significant evolution in tactics among Akira affiliates, marking the first recorded instance of such a maneuver. The use of Safe Mode in this context is more reminiscent of tactics employed by older ransomware families like Snatch and AvosLocker, indicating a possible shift in techniques as cybercriminals continue to adapt.

A Familiar Methodology with a Twist

Over the past year, Akira has emerged as a notable player in the ransomware landscape, and Huntress has been meticulously tracking its activities. Typical operations usually involve breaching networks via internet-exposed VPN appliances, with SonicWall routers being a favored target. Following the initial intrusion, Akira affiliates typically move laterally through the network, targeting the domain controller, enumerating Active Directory, exfiltrating sensitive data, and deploying encryption tools within hours.

In this recent case, the attack followed the standard protocol until it reached its final stages, where an unexpected twist occurred.

The Initial Attack: Credential Spray and Domain Controller Access

According to Huntress, the intrusion commenced in early August with a series of failed login attempts against a SonicWall SSL VPN, indicative of a credential-spraying attack. Shortly thereafter, one of these attempts succeeded, gaining access through a valid VPN account that lacked multi-factor authentication (MFA). After nearly two hours of inaction, the attacker finally logged into the domain controller via Remote Desktop Protocol (RDP), executing PowerShell commands to extract comprehensive details about every user and computer in the Active Directory—an act that aligns with the reconnaissance phase commonly observed in Akira-led attacks.

The intruder subsequently moved to an application server, installing WinRAR to compress shared files and utilizing the S3 transfer tool s5cmd to upload the acquired data to a cloud storage service controlled by the attacker. This double-extortion tactic allows them to leverage stolen data even if the victim can restore files from backups. To maintain persistent access, the attacker also installed AnyDesk, a legitimate remote access tool, used not only for real-time control but also for deploying the ransomware payload.

The Dangerous Safe Mode Strategy

In an intriguing turn of events, the attacker employed a method that avoided the necessity of creating a separate virtual machine—a tactic documented in prior Akira cases. Instead, they used the built-in Windows configuration tool (msconfig.exe) to reboot into Safe Mode with Networking. This approach effectively disabled both the Huntress agent and Microsoft Defender’s real-time protection while allowing the attacker to retain network connectivity.

Anticipating that Safe Mode would hinder their AnyDesk service, the attacker proactively made a registry entry to ensure its continued operation through the reboot. This indicates a level of planning that suggests a strategic move rather than a hasty adjustment.

Self-Sabotage: The Ransomware Fails

While the attack successfully evaded some defenses initially, it ultimately unraveled due to the very environment that was meant to protect it. Shortly after launching the akira.exe payload, the compromised host displayed "out of virtual memory" errors, leading to a premature failure of the ransomware process tree before any encryption could commence. Huntress posits that this crash stemmed from Safe Mode’s limited memory capabilities, which were insufficient to support the ransomware’s resource requirements.

Compounding the issue, a subsequent scheduled scan by Microsoft Defender identified the maligned payload nearly an hour later, categorizing it correctly as Akira. However, real-time protection remained inactive in Safe Mode, preventing immediate quarantine. The threat was only neutralized after the attacker rebooted the system back into regular operation, unwittingly restoring Defender’s protective measures and nullifying their own evasive actions.

Despite not being able to complete the encryption, the attackers had already exfiltrated sensitive Active Directory data and various file shares, leaving the victim vulnerable to extortion attempts even without the encryption of files. Experts caution that this should not be regarded as a foolproof defense; a machine with greater memory resources might still allow the ransomware to succeed in similar future attacks.

Recommendations for Organizations

In light of these findings, Huntress strongly advises organizations to enforce the implementation of MFA on all VPN accounts. They also recommend diligent monitoring for bursts of failed login attempts followed by successful ones. It is vital to ensure EDR solutions are deployed across all endpoints rather than selectively, as well as to set alerts for boot-configuration alterations and Safe Mode reboots. Additionally, monitoring Windows event logs for indications of Safe Mode activity or modifications to crucial registry keys can provide early warnings of potential intrusions.

The incident serves not only as a testament to the evolving landscape of ransomware techniques but also highlights the need for robust cybersecurity measures in the face of increasingly sophisticated threats.

Source link

Latest articles

Researchers Connect Suspected Chinese APT to Hack-for-Hire Activities

Dual Threat: Jewelbug's Cyber Espionage and Cryptocurrency Fraud Operations Security researchers from Broadcom’s Threat Hunter...

White House Approves Offensive Cyber Operations Targeting Foreign Syndicates

White House Takes Bold Action Against Foreign Cybercrime On August 12, 2026, President Donald J....

Def Con Dolt Suspected in Delta Wi-Fi Hack

In a recent roundup of cybersecurity incidents, significant events have captured attention, including a...

More like this

Researchers Connect Suspected Chinese APT to Hack-for-Hire Activities

Dual Threat: Jewelbug's Cyber Espionage and Cryptocurrency Fraud Operations Security researchers from Broadcom’s Threat Hunter...

White House Approves Offensive Cyber Operations Targeting Foreign Syndicates

White House Takes Bold Action Against Foreign Cybercrime On August 12, 2026, President Donald J....