Search/Akira Affiliate Crashes Ransomware After Attempting EDR Evasion
Story

Akira Affiliate Crashes Ransomware After Attempting EDR Evasion

An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. The attack occurred on August 4 after the hacker obtained initial access through an exposed SonicWall VPN device without multi-factor authentication (MFA). Managed detection and response (MDR) services company Huntress says that roughly two hours after a successful VPN login, the attacker connected to the domain controller via RDP, enumerated Active Directory users and computers, and then moved to an application server. They used WinRAR to archive mapped file shares and the s5cmd command-line tool to upload the stolen data to an attacker-controlled S3 bucket, before installing AnyDesk for remote access. At that stage,…

CVEs
0
Highest CVSS
In KEV
0
Sources
3
Connections
9 relationships
Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt
An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. The attack occurred on August 4 after the hacker obtained initial access through an exposed SonicWall VPN device without multi-factor authentication (MFA). Managed detection and response (MDR) services company Huntress says that roughly two hours after a successful VPN login, the attacker connected to the domain controller via RDP, enumerated Active Directory users and computers, and then moved to an application server. They used WinRAR to archive mapped file shares and the s5cmd command-line tool to upload the stolen data to an attacker-controlled S3 bucket, before installing AnyDesk for remote access. At that stage, the attacker used AnyDesk to force the compromised host to boot into Safe Mode with Networking and disable both the Huntress agent and Microsoft Defender’s real-time protection. Safe Mode is a Windows startup state designed for troubleshooting and diagnostic operations. It starts Windows with a limited set of drivers and services, generally preventing most third-party software and services from loading. For 10 minutes while in Safe Mode, "the host had no working EDR, and AV was blinded," Huntress says. Meanwhile, the attackers added AnyDesk to Windows’ Safe Mode registry, allowing it to start after reboot and retain their remote access to the breached machine. However, when they attempted to launch the main ransomware payload (akira.exe) via AnyDesk in Safe Mode, it failed to execute as the system reported low virtual memory and generated out-of-memory and PowerShell errors. A scheduled Defender scan eventually detected the Akira executable, even if real-time protection was disabled in Safe Mode, but the security tool could not remove it while the machine remained in that mode. Defender quarantined the file only after the attacker rebooted the system into normal mode, which restored real-time protection. Despite the failure to encrypt files, the Akira operator still managed to steal credentials and files for data extortion, all in less than five hours from initial access. Huntress notes that other ransomware families, such as Snatch and AvosLocker, have used this tactic for years, but this incident marks the first time the company observed it in an Akira attack. The researchers recommend adding MFA to all VPN accounts, placing credential-spraying detection measures, and monitoring for Safe Mode boot configuration changes or remote-access tools being added to the Safe Mode service registry. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 13, 2026extracted
Akira Affiliate Crashes Ransomware After Attempting EDR Evasion
A ransomware affiliate's attempt to disable security tools by rebooting a victim's system into Safe Mode backfired, with the tactic apparently preventing the malware from successfully encrypting the target's file, according to recent research by Huntress. The managed security specialist revealed in a blog post on August 12 that the Akira affiliate struck its victim in early August. A credential spraying attack enabled initial access to a SonicWall SSL VPN with no multifactor authentication (MFA) deployed. The attacker then accessed the domain controller via Remote Desktop Protocol (RDP) and began Active Directory (AD) enumeration, following a similar playbook to many Akira attacks, Huntress explained. The threat actor then moved to the application server and began collecting files, which it transferred to cloud storage using s5cmd, a fast S3 transfer utility. “This is classic double extortion activity: steal all the victims' files before encrypting them, so if the victim doesn't pay the ransom, they can threaten to post them on some sketchy underground forum or a darknet leak site,” said Huntress. However, the attack then departed from the Akira norm. Before deploying the ransomware payload, the threat actor ran msconfig.exe and forced a reboot into “Safe Mode with Networking.” “In Safe Mode, third-party services, including the Huntress agent, don't start,” noted Huntress. “Defender real-time protection was down too. For the entire Safe Mode window, the host had no working EDR, and AV was blinded.” This is a common approach for ransomware actors; in fact, it is listed by MITRE ATT&CK (T1688) as “Impair Defences: Safe Mode Boot.” Although not spotted in relation to Akira previously, the technique has been associated with groups like Snatch and AvosLocker “for years,” Huntress claimed. Unfortunately for the attackers, this move also interfered with ransomware detonation by triggering host memory errors. “Safe Mode boots with a stripped-down environment and constrained virtual memory, and the Akira process tree appears to have starved it, getting the "Out of Virtual Memory" pop-up and the cascade of PowerShell hard errors line up exactly with the moment the payload tried to kick things off,” Huntress said. “The takeaway is a little uncomfortable. While Safe Mode blinded our controls, it may also have prevented the encryption it was meant to enable. That's a lucky side effect of the attacker's own mistake in these circumstances, not a defence you can plan around.” How to Win the War Huntress was at pains to point out that future Akira victims may not be so lucky. “Ultimately, this could be a case of winning the battle, but not the war. It's possible that a host with more physical memory or a larger page file might give akira.exe enough virtual memory to encrypt the endpoint in Safe Mode,” it explained. “Akria's developers or affiliates could retool the encryptor to reduce its memory demands or make its Safe Mode launch sequence more reliable, meaning that the same failure may not occur in a future intrusion.” With this in mind, organizations should follow the report’s guidance to stay safe from attacks like this: Block credential spray attacks by alerting on bursts of failed VPN logins from a single source Correlate failed attempts with a successful login from the same IP or ASN shortly after Deploy MFA on every VPN account and disable or IP-allowlist the SSL VPN during attacks If compromised, rotate all AD and VPN credentials Use EDR on every host, as preparation often happens on unmonitored hosts Deploy SIEM and ingest VPN and Windows Event Logs, as these provide an early warning before ransomware detonation Watch for the “Safe Mode play” by flagging the following boot-configuration changes and Safe Mode boots: “msconfig.exe / bcdedit activity, Kernel-Boot EID 27 with a SAFEBOOT load option, Kernel-General EID 12 BootMode=2, and third-party security services stopping (System EID 7036)” Look out for tooling being added to the Safe Mode minimal-service registry list
infosecurity-magazine.comAug 13, 2026extracted
Akira ransomware scum blocked victim's security tools – and broke their own encryptor
ON-PREM EPA to drop requirement for public notice of polluting datacentersState and local regulators would decide whether the public gets a say on minor-source permits SYSTEMS OpenAI's upcoming Jalapeño chip looks like it'll be an inference beast128 chips, 1.7 exaFLOPS, and 27 TB of HBM give Altman and crew a leg up over Blackwell, and maybe even Rubin SYSTEMS What Nvidia's first Groq 3 LPU benchmarks tell us about its $20B gambleGemma 4 31B performance tests offer a best-case scenario for next-gen dataflow accelerators ON-PREM US datacenters tripled their water footprint in 10 years... and those are figures from the start of the AI boom. It can only be worse now. Silo-ed reporting isn't helping ai and ML AI slop is good for business if you know what you're doingYour irresponsibility is someone else's opportunity Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career Emperor Penguin Linus Torvalds banishes a bug – with a botThe lad himself finds and fixes a tricky one… or does he? FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan
theregister.comAug 12, 2026extracted
Related Stories
4
Akira Ransomware Haul Surpasses $244M in Illicit Proceeds
FBI: Akira gang has received nearly $250 million in ransoms Government agencies in the U.S. and Europe shared new information on Thursday to help organizations defend themselves against the Akira ransomware gang, which has attacked small- and medium-sized businesses since 2023. The updates to an April 2024 advisory about the group’s operations include a new list of tactics and vulnerabilities being exploited in attacks. As of late September, Akira is believed to have claimed more than $244 million in ransomware proceeds, according to the advisory. “Akira ransomware doesn’t just steal money – it disrupts the systems that power our hospitals, schools, and businesses,” said FBI Cyber Division Assistant Director Brett Leatherman. “Behind every compromised network, you’ll find real people and communities harmed by callous cyber criminals.” In addition to the FBI, the Defense Department and the Health and Human Services Department contributed to the advisory. Europol and law enforcement agencies in France, Germany and the Netherlands were also involved in the updated advisory. The group has allegedly targeted the manufacturing, education, IT and healthcare sectors. “Akira threat actors gain access to VPN products, such as SonicWall, by stealing login credentials or exploiting vulnerabilities like CVE-2024-40766,” the agencies said. “In some instances, they gain initial access through compromised VPN credentials, potentially by using initial access brokers or brute-forcing VPN endpoints. Additionally, Akira threat actors deploy password spraying techniques, using tools such as SharpDomainSpray to gain access to account credentials.” The group has also abused remote access tools like AnyDesk and LogMeIn to maintain their access to victim networks and blend in with administrator activity. In some cases, incident responders saw Akira uninstall endpoint detection and response (EDR) systems. The FBI warned that in some incidents Akira threat actors were able to steal data just two hours after initial access. The advisory links to specific advice for k-12 schools impacted by the ransomware gang. “The threat of ransomware from groups like Akira is real and organizations need to take it seriously, with swift implementation of mitigation measures,” said Nick Andersen, Executive assistant director for the cybersecurity division at the Cybersecurity and Infrastructure Security Agency. The advisory notes that Akira has ties to the now-defunct Conti ransomware gang, which launched several high-profile attacks before disbanding at the onset of Russia’s invasion of Ukraine. On a call with reporters, Andersen confirmed that Akira “may have some connections to the now defunct Conti ransomware group” but declined to say if Akira had ties to the government of Russia. The FBI’s Leatherman added that while there are no direct ties between Akira and the Russian state, they do know that the “Conti ransomware group at one point did operate within Russia and some actors may be associated with that group.” “But like with any ransomware group or variant that operates as an affiliate based program, you can have actors located anywhere across the globe. So we do believe that we likely have actors who are in a variety of different countries,” Leatherman told Recorded Future News. Researchers previously said there are deep similarities between the Akira and Conti ransomware strains. Blockchain analysis showed multiple Akira ransomware transactions to wallets associated with Conti's leadership team. Akira most recently took credit for a cyberattack on BK Technologies, a Florida-based company that makes radios for U.S. defense companies, as well as dozens of police and fire departments across the country. BK Technologies warned investors last month that it suffered a security incident in September where hackers stole non-public information and data on current and former employees. Akira has taken credit for dozens of high-profile attacks on entities like Stanford University, the Toronto Zoo, a state-owned bank in South Africa, major foreign exchange broker London Capital Group and other organizations. Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
4 shared
Nov 19, 2025
SonicWall firewall devices hit in surge of Akira ransomware attacks
Update August 05, 03:12 EDT: Cybersecurity company Huntress confirmed Arctic Wolf's findings on Monday and published a report providing indicators of compromise (IOCs) collected while investigating this campaign. Further details are available in this Reddit thread. SonicWall firewall devices have been increasingly targeted since late July in a surge of Akira ransomware attacks, potentially exploiting a previously unknown security vulnerability, according to cybersecurity company Arctic Wolf. Akira emerged in March 2023 and quickly claimed many victims worldwide across various industries. Over the last two years, Akira has added over 300 organizations to its dark web leak portal and claimed responsibility for multiple high-profile victims, including Nissan (Oceania and Australia), Hitachi, and Stanford University. The FBI says the Akira ransomware gang has collected over $42 million in ransom payments as of April 2024 from more than 250 victims. As Arctic Wolf Labs observed, multiple ransomware intrusions involved unauthorized access through SonicWall SSL VPN connections, starting on July 15. However, while a zero-day vulnerability being exploited in these attacks is very likely, Arctic Wolf has not ruled out credential-based attacks. "The initial access methods have not yet been confirmed in this campaign," the Arctic Wolf Labs researchers cautioned. "While the existence of a zero-day vulnerability is highly plausible, credential access through brute force, dictionary attacks, and credential stuffing have not yet been definitively ruled out in all cases." Throughout this surge in ransomware activity, attackers quickly transitioned from initial network access via SSL VPN accounts to data encryption, a pattern consistent with similar attacks detected since at least October 2024, indicating a sustained campaign targeting SonicWall devices. Additionally, Arctic Wolf noted the ransomware operators were observed using virtual private server hosting for VPN authentication, while legitimate VPN connections typically originate from broadband internet service providers. The security researchers are still investigating the attack methods used in this campaign and will provide additional information to defenders as soon as it becomes available. Due to the strong possibility of a SonicWall zero-day vulnerability being exploited in the wild, Arctic Wolf advised administrators to temporarily disable SonicWall SSL VPN services. Additionally, they should implement further security measures, such as enhanced logging, endpoint monitoring, and blocking VPN authentication from hosting-related network providers, until patches become available. Admins advised to secure SMA 100 appliances Arctic Wolf's report comes one week after SonicWall warned customers to patch their SMA 100 appliances against a critical security vulnerability (CVE-2025-40599) that may be exploited to gain remote code execution on unpatched devices. As the company explained, while attackers would need admin privileges for CVE-2025-40599 exploitation, and there is no evidence that this vulnerability is being actively exploited, it still urged administrators to secure their SMA 100 appliances, as they're already being targeted in attacks using compromised credentials to deploy new OVERSTEP rootkit malware according to Google Threat Intelligence Group (GTIG) researchers. SonicWall also 'strongly' advised customers with SMA 100 virtual or physical appliances to check for indicators of compromise (IoCs) from GTIG's report, suggesting that admins should review logs for unauthorized access and any suspicious activity and contact SonicWall Support immediately if they find any evidence of compromise. A SonicWall spokesperson was not immediately available for comment when contacted by BleepingComputer earlier today. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
3 shared
Aug 4, 2025
Akira ransomware exploiting critical SonicWall SSLVPN bug again
Over a year after SonicWall patched CVE-2024-40766, a critical flaw in its next-gen firewalls, ransomware attackers are still gaining a foothold in organizations by exploiting it. Like last September and earlier this year, the attackers are affiliates of the Akira ransomware-as-a-service outfit. The July 2025 surge in attacks was, according to SonicWall, facilitated by the fact that organizations has migrated from Gen 6 to Gen 7 firewalls but did not reset local user passwords (as … More → The post Akira ransomware affiliates continue breaching organizations via SonicWall firewalls appeared first on Help Net Security .
3 shared
Sep 11, 2025
Akira Ransomware’s Exploitation of SonicWall Vulnerability Continues
Akira ransomware: From SonicWall VPN login to encryption in under four hours Four hours or less: that’s how long it takes for Akira affiliates to break into organizations and deploy the ransomware on their systems, Arctic Wolf researchers have warned. Armed with SonicWall SSL VPN credentials stolen in earlier intrusions and apparently able to bypass multi-factor authentication (MFA), the attackers: Start to scan the network to discover network services and unsecured accounts Use Impacket to set up and interact with SMB sessions Use RDP for lateral movement through compromised environments Find their way to a Domain Controller and gain access to virtual machine storage and backups Create additional accounts (including domain accounts) to install RMM tools and for data exfiltration Establish a C2 method Collect and exfiltrate data Disable legitimate RMM tools and EDR tools, delete System Volume Shadow Service copies, clear event logs Install WinRAR to archive data that will be exfiltrated via rclone or FileZilla to a virtual private server (VPS) they control Deploy the Akira ransomware. Initial access Arctic Wolf has been warning about the increase of Akira ransomware attacks since July 2025. At first, it appeared the attackers might be exploiting a zero-day in SonicWall VPN devices, but it was later confirmed they were abusing CVE-2024-40766, an improper access control flaw in SonicWall SonicOS management access and SSL VPN. A fix for CVE-2024-40766 was released by SonicWall in August 2024 but, according to the company, some customers have upgraded from Gen 6 to Gen 7 firewalls without resetting passwords for local user accounts with SSL VPN access. The prevailing theory is that these actors harvested SSL VPN and privileged service account credentials months earlier during quieter intrusions. They are now reusing those credentials to breach organizations that may have patched or upgraded, but never rotated local user passwords. Rapid7 researchers have also suggested that attackers are exploiting additional weaknesses, including: A misconfiguration in SonicWall devices’ SSLVPN Default Users Group setting, which automatically adds every successfully authenticated LDAP user to a predefined local group that may have access to sensitive services Externally accessible Virtual Office Portal inside the SonicOS management interface, which allows them to configure one-time password (OTP) multi-factor authentication on compromised accounts. “In our investigation, we observed repeated malicious SSL VPN logins on accounts with OTP MFA enabled, ruling out scratch code usage in those cases. We also found no signs of malicious use of the compromised accounts prior to SSL VPN login (event ID 1080), nor did we observe unauthorized OTP unbinding events or other malicious configuration changes (event ID 1382) in the five days leading up to the intrusions,” Arctic Wolf researchers noted. “Taken together, the evidence points to the use of valid credentials rather than modification of OTP configuration, though the exact method of authenticating against MFA-enabled accounts remains unclear.” So far, there’s no indication that these intrusions and the attack against SonicWall’s cloud backup service for firewalls are related. Advice for organizations Victim organizations span multiple industries and vary in size, which points to the attacks being opportunistic rather than targeted. The extraordinarily short time between initial access and ransomware deployment means that early detection and response are crucial. The researchers advise organizations to: Monitor for or, if possible, block logins from VPS hosting providers Monitor for anomalous SMB activity that points to Impacket use and for LDAP discovery activity Monitor for execution of network scanning tools and archival tools from unusual locations on servers Use App Control for Business to block unauthorized remote tools, deny execution from untrusted paths, etc. “If your SonicWall devices have previously run firmware versions vulnerable to CVE-2024-40766, we strongly recommend resetting all credentials stored on the firewall, including SSL VPN passwords and OTP MFA secrets,” Arctic Wolf researchers added. “This includes both local firewall accounts and LDAP-synchronised Active Directory accounts, especially where accounts have access to SSL VPN. Threat actors are abusing these credentials even when devices are fully patched, suggesting that credential theft may have occurred earlier in the lifecycle. Resetting LDAP synchronisation accounts is especially critical, as we have observed logins against these accounts despite them not being intended for VPN access.” Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
3 shared
Sep 29, 2025