Akira Ransomware Uses Safe Mode to Bypass EDR
ID: 7809424e-e04b-5d0a-962a-7b0f2c12b437
STIX ID: report--7809424e-e04b-5d0a-962a-7b0f2c12b437
Feed Name: Security Affairs
Akira ransomware operators gained access via an MFA-less SonicWall VPN, exfiltrated data (Active Directory and mapped shares), then rebooted a compromised host into Safe Mode with Networking and added AnyDesk to the Safe Mode registry to disable EDR and maintain access; the Akira encryptor failed seconds after launching due to out-of-virtual-memory errors in the constrained Safe Mode environment, but the attacker’s exfiltration still enables extortion. Detection guidance highlights monitoring for bcdedit/msconfig use, Kernel Boot/General event IDs indicating Safe Mode, third-party service stops, and remote-access tools added to Safe Mode registry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
