Akira attackers disable EDR via Safe Mode boot
๐ An Akira ransomware affiliate disabled endpoint detection by rebooting a compromised host into Safe Mode with Networking after gaining access through an exposed SonicWall VPN lacking MFA. The operators used tools like WinRAR and s5cmd to archive and exfiltrate mapped shares to an attacker-controlled S3 bucket, then installed AnyDesk for remote control. While Safe Mode blinded EDR and real-time AV, the Akira payload failed to run due to low virtual memory; defenders later quarantined the file after a normal reboot. Huntress recommends enforcing MFA on VPNs, monitoring for Safe Mode registry changes, and detecting credential abuse.
