Akira Ransomware Disables EDR Using Windows Safe Mode
TL;DR. Akira ransomware affiliates exploited Windows Safe Mode to disable Endpoint Detection and Response (EDR) solutions, allowing data theft before encryption failed due to system errors. - Attackers gained initial access via an unauthenticated SonicWall VPN, then moved to domain and application servers. - They used AnyDesk to force a Safe Mode reboot, bypassing EDR and real-time antivirus protection. - Despite stealing credentials and files, the ransomware payload failed to encrypt due to low virtual memory. - This incident highlights a known tactic adopted by Akira, previously seen with Snatch and AvosLocker.
- Akira ransomware affiliates used Safe Mode with Networking to bypass EDR and antivirus.
- The attack exploited an unauthenticated SonicWall VPN for initial access.
- Data exfiltration occurred before the ransomware encryption payload failed.
- Security firms recommend monitoring for Safe Mode boot changes and enforcing MFA on VPNs.
Sources
- Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt — bleepingcomputer.com