< Back to all clusters
[TECHNOLOGY] · 4 sources

started · updated

Akira ransomware uses Windows Safe Mode to bypass security tools

Akira ransomware affiliates have developed a new tactic to bypass security by rebooting compromised systems into Windows Safe Mode with Networking. This method aims to disable third-party endpoint detection and response (EDR) tools, which often remain offline during Safe Mode, before launching the encryption process.

In a recent incident identified by Huntress, the attack began via a credential-spraying campaign against a SonicWall SSL VPN that lacked multi-factor authentication (MFA). Once access was gained, the intruder used Remote Desktop Protocol (RDP) to reach a domain controller, where they exported Active Directory data including user accounts and system information. The attackers also installed AnyDesk to facilitate remote control and file transfers.

While the specific attempt to encrypt files failed because the Safe Mode environment also inadvertently broke the ransomware's encryptor, the breach was still successful in other ways. The attackers had already stolen credentials and sensitive data from network shares for potential extortion. Security analysts warn that this is not a reliable defense, as future iterations of the malware may be optimized to function more effectively in Safe Mode.

Entities

Akira · Huntress · SonicWall · Windows