Akira Ransomware Disables EDR Using Windows Safe Mode

TL;DR. Akira ransomware affiliates exploited Windows Safe Mode to disable Endpoint Detection and Response (EDR) solutions, allowing data theft before encryption failed due to system errors. - Attackers gained initial access via an unauthenticated SonicWall VPN, then moved to domain and application servers. - They used AnyDesk to force a Safe Mode reboot, bypassing EDR and real-time antivirus protection. - Despite stealing credentials and files, the ransomware payload failed to encrypt due to low virtual memory. - This incident highlights a known tactic adopted by Akira, previously seen with Snatch and AvosLocker.

Sources

Back to QLANKR News