Ransomware gang crashes own attack — with no-one to blame but themselves
Akira ransomware tried Safe Mode boot to disable defenses but broke its own encryptor Defender later flagged and quarantined payload, leaving attackers with only stolen data Huntress advises VPN brute‑force alerts, MFA, SIEM logging, and Safe Mode monitoring A recent ransomware attack saw the operators Akira (figuratively) shoot themselves in the foot - and they still walked away with sensitive data, albeit limping.
Akira is a well-known ransomware group, considered one of the most active cybercriminal organizations on the internet.
Its modus operandi is simple in theory: they look for an exposed VPN instance (for example, one with a default or weak password), access the domain controller, enumerate Active Directory, steal sensitive data, and deploy an encryptor.
With the encryptor they leave a ransom note, instructing the victim to reach out and negotiate a payment in exchange for the decryption key and for deleting the stolen documents and information.
However, in a recent attack, they tried to first disable the device’s antivirus and endpoint detection and response (EDR) solutions.
The process backfired, resulting in the security solutions successfully spotting and quarantining the encryptor.
The good and the bad of Safe Mode with Networking A new report published by security researchers Huntress said that after establishing persistence on a device, Akira rebooted it into Safe Mode with Networking.
This Windows startup mode boots the OS with only the essential drivers and services, excluding important components such as antivirus programs or EDR agents.
At the same time, it grants internet access which, for Akira, is the perfect combination.
“This means Defender real-time protection was down too,” Akira explained.
“For the entire Safe Mode window, the host had no working EDR, and AV was blinded.
This is MITRE ATT&CK T1688: Impair Defenses: Safe Mode Boot, a technique that ransomware families like Snatch and AvosLocker have used for years.
However, this is the first time we have seen Akira use it.” What Akira didn’t bank on was Safe Mode with Networking also preventing its encryptor from running.
“Safe Mode boots with a stripped-down environment and constrained virtual memory, and the Akira process tree appears to have starved it, getting the "Out of Virtual Memory" pop-up and the cascade of PowerShell hard errors line up exactly with the moment the payload tried to kick things off.” The operators had no other choice but to boot the device back up normally, at which point a scheduled Defender scan detected the encryptor, flagged it, and ultimately quarantined it.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.