Akira ransomware attack used Windows Safe Mode to bypass EDR

 

Akira ransomware attack used Windows Safe Mode to bypass EDR

An Akira ransomware affiliate disabled security tools on a compromised system by restarting it into Windows Safe Mode with Networking, according to a report from cybersecurity firm Huntress.

The attack began on August 4 when the intruder gained access via an exposed SonicWall VPN without multi-factor authentication (MFA). About two hours later, the attacker accessed the domain controller through RDP, searched for users and computers, and moved to an application server.

The attacker used WinRAR to archive files and the s5cmd tool to upload stolen data to an attacker-controlled S3 bucket. They also installed AnyDesk to maintain remote access.

Using AnyDesk, the attacker restarted the system into Safe Mode with Networking and disabled the Huntress security agent and Microsoft Defender's real-time protection leaving machine without working EDR protection for about 10 minutes.

The attacker also added AnyDesk to the Windows Safe Mode registry so it would continue running after the reboot. However, the main Akira ransomware file failed to run because the system reported low virtual memory and other errors.

Microsoft Defender later detected the ransomware file during a scheduled scan. It could not remove the file while the system was in Safe Mode, but successfully quarantined it after the attacker rebooted the machine.

Although the ransomware failed to encrypt files, the attacker still stole credentials and data for extortion. The entire intrusion took less than five hours from initial access.

Huntress said other ransomware groups, including Snatch and AvosLocker, have used Safe Mode to bypass security tools. The company recommends enabling MFA on VPN accounts and monitoring for suspicious Safe Mode changes and remote-access software.


Back to the list