Ransomware gang crashes own attack — with no-one to blame but themselves
In a new attack, Akira disables EDR tools, but kills the encryptor, as well, as researchers still warn of a worrying practice.
In a recent ransomware attack, the Akira group inadvertently sabotaged their own operation. The cybercriminals attempted to disable security defenses by booting the infected device into Safe Mode with Networking. This typically disables antivirus and endpoint detection and response (EDR) programs, creating an opening for the ransomware to execute.
However, Akira's encryptor failed to launch, as the Safe Mode environment lacked sufficient virtual memory. Consequently, the attackers were forced to reboot the system normally, allowing Defender to detect and quarantine the malicious code. Huntress, a cybersecurity firm, has warned organizations about this particular vulnerability, recommending a series of proactive measures to prevent such incidents.
These include setting up alerts for failed VPN login attempts, enforcing multi-factor authentication (MFA), disabling or IP-allowlisting SSL VPNs during active attacks, rotating AD and VPN credentials, and deploying EDR on every host. Additionally, SIEM logging and monitoring VPN and Windows event logs are suggested to detect any suspicious activities early on.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.