An Akira ransomware affiliate attempted to disable security software by rebooting a compromised host into Safe Mode, but the tactic caused the encryption payload to crash from memory exhaustion.
Key Points
- Attackers gained initial access on August 4 by exploiting an MFA-less SonicWall VPN to steal credentials and exfiltrate data via an S3 bucket.
- The affiliate rebooted the victim host into Safe Mode with Networking to disable EDR and Microsoft Defender real-time protection.
- The ransomware process failed 13 seconds after launch due to an "out-of-virtual-memory" error caused by the restricted Safe Mode environment.
- Attackers maintained persistence by adding AnyDesk to the Safe Mode registry before the reboot.
- Huntress researchers identified this as the first observed instance of Akira using Safe Mode to bypass security controls.