First Akira Safe Mode attack disables endpoint detection and response but fails to encrypt, Huntress says
Huntress Labs Inc. said today that an Akira ransomware affiliate rebooted a victim’s Windows server into Safe Mode to knock its endpoint security offline — and it worked. The same reboot also broke the ransomware. Safe Mode loads only core Windows drivers and services. Third-party security products sit outside that minimal set by design. That […] The post First Akira Safe Mode attack disables…
Huntress Labs reported that the Akira ransomware affiliate recently used Safe Mode to disable endpoint detection and response on a victim's Windows server. Safe Mode loads only core Windows drivers and services, leaving third-party security products outside that minimal set. This technique, cataloged as MITRE T1688, has been previously abused by Snatch and AvosLocker.
The Akira attack entered through a SonicWall SSL VPN with no multifactor authentication, allowing brute force login attempts. After several failed attempts, a valid account gained access. The operator then used Remote Desktop Protocol on the domain controller, opened an elevated command prompt, and pinged an internal address. They also enumerated Active Directory properties and collected data in text files.
The attacker installed WinRAR, staged archives on an attacker-controlled S3 bucket, and installed AnyDesk as a service, keeping the remote-access channel alive through the reboot. The compromised host showed Safe Mode load option and BootMode 2, but Defender logged an error stating the service couldn't be started in Safe Mode. A PowerShell failure to create a new guard page for the stack occurred, limiting the encryptor's capabilities.
The host restarted, restored real-time protection, and the Akira process tree began, but the encryption failed due to limited memory in Safe Mode. Huntress recommends multifactor authentication for VPN accounts, alerts on failed login bursts, and EDR coverage for better protection.
Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.