An Akira ransomware affiliate bypassed endpoint detection and response (EDR) solutions by rebooting a compromised system into Safe Mode with Networking. This action disabled both the Huntress agent and Microsoft Defender's real-time protection for approximately 10 minutes, creating a window for malicious activity without detection.
The attack began on August 4, with initial access obtained through an exposed SonicWall VPN device lacking multi-factor authentication (MFA). After gaining access, the attacker connected to the domain controller, enumerated Active Directory, and moved to an application server. They used WinRAR to archive mapped file shares and s5cmd to upload stolen data to an S3 bucket, then installed AnyDesk for remote access. The attackers then used AnyDesk to force the system into Safe Mode with Networking.
While in Safe Mode, the attackers added AnyDesk to the Windows Safe Mode registry to maintain remote access. However, their attempt to launch the Akira ransomware payload (akira.exe) failed. The system reported low virtual memory and generated out-of-memory and PowerShell errors, preventing the encryption of files. Microsoft Defender, despite its real-time protection being disabled, eventually detected the Akira executable during a scheduled scan, but could only quarantine it after the system was rebooted into normal mode, restoring real-time protection.
Despite the failure to encrypt files, the Akira operator successfully stole credentials and files for data extortion within five hours of initial access. Huntress noted that this tactic of using Safe Mode to disable security tools has been observed with other ransomware families like Snatch and AvosLocker, but this is the first time it has been seen in an Akira attack. Researchers recommend implementing MFA for all VPN accounts and deploying credential-spraying detection measures to mitigate similar threats.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
An Akira ransomware affiliate disabled endpoint detection and response (EDR) by restarting a compromised system into Safe Mode with Networking, allowing data exfiltration. Although the ransomware payload failed to execute due to low virtual memory, the attackers successfully stole credentials and files. This incident highlights a known tactic, previously seen with other ransomware families, now observed in an Akira attack.