Akira Ransomware Exploits Safe Mode to Bypass Security Tools, Fails to Encrypt
Akira ransomware affiliate attempted to disable security tools by forcing a compromised system into Safe Mode with Networking, but the encryption process ultimately failed.
A Five-Hour Timeline from Initial Access to Data Exfiltration
The breach commenced when the attacker exploited an unsecured SonicWall VPN device lacking multi-factor authentication, a common vulnerability in ransomware attacks. Within two hours of gaining entry, the threat actor connected to the organization’s domain controller via Remote Desktop Protocol, conducted Active Directory enumeration, and moved laterally to an application server. Using the WinRAR archiving tool, the attacker compressed files from mapped network shares and uploaded the data to a cloud storage bucket controlled by the adversary. To maintain access, the attacker installed AnyDesk, a remote access tool frequently abused by ransomware groups, ensuring continued control over the compromised system.
Exploiting Safe Mode to Circumvent Security Software
The attacker then leveraged AnyDesk to reboot the system into Safe Mode with Networking, a Windows diagnostic mode that loads minimal drivers and services. This step aimed to disable endpoint detection and response tools. Crucially, the adversary modified the Windows registry to ensure AnyDesk remained active in this restricted environment, preserving remote access. When the attacker attempted to execute the Akira ransomware payload in Safe Mode, the process failed due to insufficient virtual memory and operational errors. Despite this, the security software later detected the ransomware executable during a scheduled antivirus scan, though it could not remove the file until the attacker disabled Safe Mode.
Data Theft Occurred Despite Failed Encryption
Although the encryption phase failed, the attacker successfully exfiltrated sensitive data and credentials within five hours of initial access. Huntress noted that while other ransomware groups like Snatch and AvosLocker have previously used Safe Mode evasion tactics, this marked the first observed instance of an Akira affiliate employing the technique. The increasing use of built-in operating system features for evasion highlights a shift in ransomware strategies, complicating detection for security teams reliant on signature-based defenses.
Akira’s Ongoing Global Threat Profile
Since its emergence in March 2023, Akira has become a prominent ransomware-as-a-service operation, with law enforcement estimating over $244 million in ransom payments collected. The group consistently targets sectors such as manufacturing, professional services, technology, and financial institutions. A recurring tactic involves exploiting VPNs without multi-factor authentication, as demonstrated in this incident. Security experts advise organizations to enforce MFA for all VPN access, implement detection for credential-spraying attempts, and monitor for unauthorized changes to Safe Mode configurations or the addition of remote access tools in the registry. These measures are critical for identifying and mitigating similar evasion techniques.
Huntress noted that while other ransomware groups like Snatch and AvosLocker have previously used Safe Mode evasion tactics, this marked the first observed instance of an Akira affiliate employing the technique.
