Akira ransomware scum blocked victim's security tools – and broke their own encryptor
Gives a whole new meaning to Safe Mode
An Akira ransomware affiliate infiltrated a victim's network by exploiting a SonicWall SSL VPN, gaining access to the domain controller and stealing credentials and data from file shares. The attacker then forced the system to reboot into Safe Mode with Networking, a boot mode designed to disable most third-party software, in an attempt to kill security tools and break the ransomware's encryptor.
However, this maneuver also impaired the ransomware's own encryption capabilities, as the limited memory in Safe Mode was insufficient to perform the encryption. Despite this setback for the attacker, the victim still fell prey to the breach, as the attacker had already exfiltrated sensitive data before being blocked by Safe Mode.
Security experts recommend implementing multi-factor authentication (MFA) to prevent such attacks, as well as monitoring for Safe Mode boot changes and third-party security services disabling.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.