Akira ransomware affiliate’s Safe Mode reboot disables security tools but stalls encryption
An Akira ransomware operator forced a victim machine into Safe Mode, shutting down security software but also preventing the ransomware from encrypting files.
Huntress investigators traced an Akira ransomware intrusion that began with a credential-spray attack on a SonicWall SSL VPN, where a valid account without multi-factor authentication was used to gain RDP access to the domain controller. The intruder enumerated Active Directory, archived shared files with WinRAR, and exfiltrated them via the s5cmd S3 utility, while also installing AnyDesk as a backdoor. The ransomware binary, akira.exe, was dropped, and the attacker then rebooted the endpoint into Safe Mode with Networking to neutralize endpoint detection and response tools, including the Huntress agent and Microsoft Defender.
The constrained virtual memory in Safe Mode triggered memory errors, stopping the encryption process, though the attacker had already stolen credentials and data. Analysts suggest that machines with more RAM or a modified encryptor could still succeed, and they recommend monitoring for Safe Mode boot events and enforcing MFA on VPN accounts.
Why it matters
It shows how attackers exploit system boot modes and highlights the need for MFA and vigilant monitoring to protect against ransomware.
In this story