Cybersecurity

Akira Attackers Disable EDR Systems via Safe Mode and Steal Data Without Encrypting It

A partner of the Akira ransomware operation exploited an exposed SonicWall VPN device without multifactor authentication to access the victim’s network, then disabled security tools by rebooting the system into Safe Mode. The attackers successfully stole data and credentials in less than five hours, but the ransomware payload failed to encrypt files because of memory-related errors.

2026-08-13
3 min read
7 views
فريق تحرير certi.news
Akira Attackers Disable EDR Systems via Safe Mode and Steal Data Without Encrypting It

A partner of the Akira ransomware operation managed to disable the endpoint detection and response (EDR) solution on a compromised system by rebooting the device into “Safe Mode with Networking,” before stealing files and credentials from the targeted environment. The attack occurred on August 4, after the attacker gained initial access through an exposed SonicWall VPN device that was not protected by multifactor authentication.

Managed detection and response company Huntress said the attacker connected to the domain controller via Remote Desktop Protocol (RDP) about two hours after successfully logging in to the virtual private network. The attacker then inventoried users and computers in Active Directory before moving to an application server.

Intrusion and Data Theft Timeline

The attackers used WinRAR to archive the associated file shares, then used the s5cmd command-line tool to upload the stolen data to an S3 bucket under their control. They also installed AnyDesk to provide remote access to the compromised device.

At a later stage, the attackers used AnyDesk to force the device to boot into Safe Mode with Networking, which disabled the Huntress agent and Microsoft Defender real-time protection. In this mode, Windows starts with a limited set of drivers and services, which typically prevents many third-party software programs and services from loading.

According to Huntress, the device remained without active EDR for 10 minutes, while real-time antivirus protection was unable to operate. To maintain remote access after the reboot, the attackers added AnyDesk to the Windows registry for Safe Mode services, causing the program to start automatically in that mode.

Encryption Failure Does Not Mean the Attack Failed

When the attackers attempted to run the main ransomware payload, named akira.exe, through AnyDesk while the system was in Safe Mode, the operation failed. The system reported low virtual memory, along with out-of-memory errors and PowerShell-related errors.

A scheduled Microsoft Defender scan detected the Akira file, despite real-time protection being disabled in Safe Mode, but the tool could not remove the file while the device remained in that mode. After the attacker rebooted the system into normal mode, real-time protection resumed operation and Defender was able to quarantine the file.

Although the files were not encrypted, Akira operators successfully stole credentials and files for use in data-leak extortion within less than five hours of the initial access. Huntress says that other ransomware families, including Snatch and AvosLocker, have used this technique for years, but this incident was the first time the company observed it being used in an Akira attack.

Recommendations for Monitoring the Technique

Huntress recommends that organizations take the following actions:

  • Add multifactor authentication to all VPN accounts.
  • Implement mechanisms to detect password-spraying attempts.
  • Monitor changes to Safe Mode boot settings.
  • Monitor the addition of remote-access tools to the Safe Mode services registry.

The incident highlights that disabling encryption does not eliminate the impact of a ransomware compromise; attackers can continue stealing files and credentials even when the main payload fails to carry out the encryption process.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news