Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Google Targets 2027 for First Major Post-Quantum Security Milestone

August 13, 2026

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

August 13, 2026

Exposed AWS Access Key Linked to Data Breach Affecting 1500+ UK Charit

August 13, 2026
Facebook X (Twitter) Instagram
Friday, August 14
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Akira Affiliate Crashes Ransomware After Attempting EDR Evasion
News

Akira Affiliate Crashes Ransomware After Attempting EDR Evasion

Team-CWDBy Team-CWDAugust 13, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A ransomware affiliate’s attempt to disable security tools by rebooting a victim’s system into Safe Mode backfired, with the tactic apparently preventing the malware from successfully encrypting the target’s file, according to recent research by Huntress.

The managed security specialist revealed in a blog post on August 12 that the Akira affiliate struck its victim in early August.

A credential spraying attack enabled initial access to a SonicWall SSL VPN with no multifactor authentication (MFA) deployed.

The attacker then accessed the domain controller via Remote Desktop Protocol (RDP) and began Active Directory (AD) enumeration, following a similar playbook to many Akira attacks, Huntress explained.

The threat actor then moved to the application server and began collecting files, which it transferred to cloud storage using s5cmd, a fast S3 transfer utility.

“This is classic double extortion activity: steal all the victims’ files before encrypting them, so if the victim doesn’t pay the ransom, they can threaten to post them on some sketchy underground forum or a darknet leak site,” said Huntress.

Read more on EDR evasion: Ransomware Groups Increasingly Deploy EDR Kill Techniques

However, the attack then departed from the Akira norm. Before deploying the ransomware payload, the threat actor ran msconfig.exe and forced a reboot into “Safe Mode with Networking.”

“In Safe Mode, third-party services, including the Huntress agent, don’t start,” noted Huntress. “Defender real-time protection was down too. For the entire Safe Mode window, the host had no working EDR, and AV was blinded.”

This is a common approach for ransomware actors; in fact, it is listed by MITRE ATT&CK (T1688) as “Impair Defences: Safe Mode Boot.” Although not spotted in relation to Akira previously, the technique has been associated with groups like Snatch and AvosLocker “for years,” Huntress claimed.

Unfortunately for the attackers, this move also interfered with ransomware detonation by triggering host memory errors.

“Safe Mode boots with a stripped-down environment and constrained virtual memory, and the Akira process tree appears to have starved it, getting the “Out of Virtual Memory” pop-up and the cascade of PowerShell hard errors line up exactly with the moment the payload tried to kick things off,” Huntress said.

“The takeaway is a little uncomfortable. While Safe Mode blinded our controls, it may also have prevented the encryption it was meant to enable. That’s a lucky side effect of the attacker’s own mistake in these circumstances, not a defence you can plan around.”

How to Win the War 

Huntress was at pains to point out that future Akira victims may not be so lucky.

“Ultimately, this could be a case of winning the battle, but not the war. It’s possible that a host with more physical memory or a larger page file might give akira.exe enough virtual memory to encrypt the endpoint in Safe Mode,” it explained. 

“Akria’s developers or affiliates could retool the encryptor to reduce its memory demands or make its Safe Mode launch sequence more reliable, meaning that the same failure may not occur in a future intrusion.”

With this in mind, organizations should follow the report’s guidance to stay safe from attacks like this:

  • Block credential spray attacks by alerting on bursts of failed VPN logins from a single source
  • Correlate failed attempts with a successful login from the same IP or ASN shortly after
  • Deploy MFA on every VPN account and disable or IP-allowlist the SSL VPN during attacks
  • If compromised, rotate all AD and VPN credentials
  • Use EDR on every host, as preparation often happens on unmonitored hosts
  • Deploy SIEM and ingest VPN and Windows Event Logs, as these provide an early warning before ransomware detonation
  • Watch for the “Safe Mode play” by flagging the following boot-configuration changes and Safe Mode boots: “msconfig.exe / bcdedit activity, Kernel-Boot EID 27 with a SAFEBOOT load option, Kernel-General EID 12 BootMode=2, and third-party security services stopping (System EID 7036)”
  • Look out for tooling being added to the Safe Mode minimal-service registry list



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
Next Article Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Team-CWD
  • Website

Related Posts

News

Google Targets 2027 for First Major Post-Quantum Security Milestone

August 13, 2026
News

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

August 13, 2026
News

Exposed AWS Access Key Linked to Data Breach Affecting 1500+ UK Charit

August 13, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Beware of threats lurking in booby-trapped PDF files

October 7, 2025

What parents should know to protect their children from doxxing

November 28, 2025

The quest for greater tech independence

May 19, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.