Akira ransomware reboots into Windows Safe Mode to knock EDR offline

Summary

Akira ransomware affiliates are now utilizing a new tactic to bypass endpoint detection and response (EDR) systems by rebooting compromised Windows systems into Safe Mode with Networking. This technique has been observed disabling both Huntress's agent and Microsoft Defender's real-time protection, allowing attackers a window to operate without immediate detection. The observed incident began with a credential-spraying attack against an exposed SonicWall SSL VPN, leading to RDP access, data archiving, and ransomware deployment.

IFF Assessment

FOE

This article details a new and effective evasion technique used by the Akira ransomware, posing a significant threat to defenders by circumventing EDR solutions.

Defender Context

Defenders need to be aware of ransomware groups leveraging Windows Safe Mode as an evasion technique to disable security software. This highlights the need for robust post-compromise detection strategies and potentially alternative methods to monitor or protect critical systems even when EDR is offline.

Read Full Story →