Akira’s Safe Mode play blinds EDR but crashes its own encryptor

Huntress says an Akira affiliate rebooted a victim into Safe Mode to kill EDR, then the encryptor crashed on the constrained environment.

CSBadmin
2 Min Read

Huntress has documented an Akira ransomware affiliate forcing a compromised Windows machine into Safe Mode with Networking, a first for the gang, in an attempt to strip endpoint defenses. The twist: the constrained boot environment broke the encryptor itself.

The incident began August 4 with a credential-spraying attack against an exposed SonicWall SSL VPN. About seven minutes after the failed logins started, the attacker authenticated to an account that had no multi-factor authentication enabled. Within two hours the operator was on the domain controller over RDP, enumerating Active Directory, then moved to an application server to archive mapped file shares with WinRAR and upload the stolen data to an attacker-controlled S3 bucket using s5cmd, setting up a double-extortion play.

After installing AnyDesk for persistent access, the operator used msconfig.exe to force a reboot into Safe Mode instead of disabling security tools directly. The reboot stopped the Huntress agent and disabled Microsoft Defender’s real-time protection. Safe Mode loads only essential drivers and services, which is why many third-party security products drop out, a technique previously tied to Snatch and AvosLocker and tracked by MITRE as T1688.

Thirteen seconds after the reboot, the machine began throwing virtual memory errors. Akira’s encryptor relies on concurrent worker threads and heavy memory mapping, a design that choked on Safe Mode’s minimal driver set and limited pagefile. Defender only managed to quarantine the binary after the attacker rebooted back into normal Windows.

Huntress cautioned against reading the failure as a defense: more memory or a retooled encryptor could make Safe Mode detonation work next time. The priority is catching the intrusion before the reboot, so organizations should require MFA on every VPN account, correlate bursts of failed logins with later successes, and alert on msconfig or bcdedit activity and Safe Mode boot events.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.