started · updated
Akira ransomware uses Safe Mode to bypass security tools
Akira ransomware affiliates are utilizing a sophisticated evasion technique by forcing compromised Windows systems into Safe Mode with Networking. By using tools such as bcdedit and msconfig.exe to modify boot configurations, attackers can effectively neutralize endpoint detection and response (EDR) solutions, including Microsoft Defender and Huntress, which often fail to load essential drivers or services in a minimal startup environment.
The attack chain typically begins with initial access gained through credential spraying against VPN devices, such as SonicWall, that lack multi-factor authentication (MFA). Once inside, attackers move laterally via Remote Desktop Protocol (RDP), archive file shares using WinRAR, and exfiltrate data to attacker-controlled Amazon S3 buckets using the s5cmd tool. To maintain control during the evasion phase, attackers may install remote access tools like AnyDesk and modify registry keys to ensure they persist even after a reboot into Safe Mode.
While this method successfully blinds security telemetry, the final encryption phase has shown instability. In observed cases, the akira.exe ransomware payload failed to execute within Safe Mode due to system errors related to low virtual memory and PowerShell failures.
Entities
Akira · Amazon S3 · Huntress · Microsoft Defender · SonicWall