Particle.news
Download on the App Store

Akira Affiliate Reboots Host Into Safe Mode to Disable EDR and Crashes Its Own Encryptor

Huntress says the Safe Mode reboot blinded endpoint defenses, caused the Akira payload to run out of virtual memory, leaving stolen files exposed for extortion.

Overview

  • In early August attackers used credential spraying against an internet‑exposed SonicWall SSL VPN with no multi‑factor authentication, then RDP'd to the domain controller and performed Active Directory enumeration.
  • The actor moved to an application server, used WinRAR to archive mapped shares and employed the s5cmd tool to upload the stolen archives to an attacker‑controlled Amazon S3 bucket for double‑extortion leverage.
  • Before launching the encryptor the intruder ran msconfig to force a reboot into Windows Safe Mode with Networking and added AnyDesk to the Safe Mode service registry to preserve remote access.
  • Safe Mode stopped third‑party EDR and Defender real‑time protection but also constrained virtual memory so the akira.exe process hit out‑of‑memory errors and failed to encrypt files; Defender later quarantined the binary after a normal reboot restored protections.
  • Huntress warns the failed encryption was accidental and recommends immediate steps including enforcing VPN MFA, alerting on credential‑spray login bursts and Safe Mode boot/config changes, deploying EDR on every host, and monitoring S3 egress and relevant Windows event logs because attackers may refine this technique.