An Akira ransomware affiliate used Windows Safe Mode with Networking to disable security tools after accessing a network through an exposed SonicWall VPN device. The attackers stole files and credentials, but their encryption payload failed to run.

Akira attackers access network through exposed VPN

The Akira ransomware Safe Mode attack began on 4 August when an affiliate logged in through a SonicWall VPN account without multi-factor authentication.

Around two hours later, the attacker connected to the domain controller through Remote Desktop Protocol. They enumerated Active Directory users and computers before moving to an application server.

The attackers used WinRAR to archive mapped file shares. They then used the s5cmd command-line tool to upload the stolen data to an attacker-controlled Amazon S3 bucket.

They also installed AnyDesk to maintain remote access to the compromised environment.

Safe Mode disables EDR and real-time protection

The Akira operator used AnyDesk to restart the compromised host in Safe Mode with Networking. This Windows startup mode loads a limited set of drivers and services, which can prevent third-party security software from starting.

Once the device entered Safe Mode, the attackers disabled the Huntress agent and Microsoft Defender real-time protection. For roughly 10 minutes, the affected machine had no active endpoint detection and response protection.

The attackers also added AnyDesk to the Safe Mode registry. This allowed the remote-access tool to launch after a reboot and helped them retain control of the system.

Security researchers have previously seen ransomware groups such as Snatch and AvosLocker use Safe Mode to bypass endpoint protection. However, this marks the first Akira incident of this kind observed by Huntress.

Ransomware payload fails because of memory errors

The attackers attempted to launch the main Akira ransomware executable through AnyDesk while the system remained in Safe Mode.

The encryption attempt failed. Windows reported low virtual-memory conditions and generated out-of-memory and PowerShell errors, preventing the ransomware from executing successfully.

A scheduled Microsoft Defender scan later detected the Akira executable. Although Defender could identify the file, it could not quarantine it while the system continued to run in Safe Mode.

The attacker eventually rebooted the system into normal mode. That action restored real-time protection and allowed Defender to quarantine the ransomware payload.

Data theft still enables extortion

The failed encryption attempt did not prevent the attackers from causing serious harm. During the intrusion, which lasted less than five hours, they stole credentials and files that could support a data-extortion campaign.

The incident shows why organisations should not treat a failed ransomware deployment as a contained event. Attackers may still possess sensitive files and use them to pressure victims into paying.

Organisations can reduce exposure by requiring multi-factor authentication for every VPN account. Security teams should also monitor for password-spraying activity, unexpected Safe Mode boot changes and remote-access software added to Safe Mode registry settings.


0 responses to “Akira ransomware disables EDR in Safe Mode but fails to encrypt files”