AUTO-UPDATED

Akira Ransomware Uses Safe Mode to Bypass EDR

An Akira ransomware affiliate attempted to disable security software by rebooting a compromised host into Safe Mode, but the tactic caused the encryption payload to crash from memory exhaustion.

Key Points

  • Attackers gained initial access on August 4 by exploiting an MFA-less SonicWall VPN to steal credentials and exfiltrate data via an S3 bucket.
  • The affiliate rebooted the victim host into Safe Mode with Networking to disable EDR and Microsoft Defender real-time protection.
  • The ransomware process failed 13 seconds after launch due to an "out-of-virtual-memory" error caused by the restricted Safe Mode environment.
  • Attackers maintained persistence by adding AnyDesk to the Safe Mode registry before the reboot.
  • Huntress researchers identified this as the first observed instance of Akira using Safe Mode to bypass security controls.

Why it Matters

While the ransomware failed in this specific instance, the tactic demonstrates an evolving threat where attackers intentionally manipulate system boot states to blind security software. Organizations cannot rely on such technical glitches for protection, as future iterations of the malware could be optimized to function within the memory constraints of Safe Mode.
Securityaffairs.com Published by Pierluigi Paganini
Read original