Akira ransomware is employing a novel technique to undermine Windows defenses before encrypting files. By rebooting compromised systems into Safe Mode with Networking, attackers maintain network connectivity while rendering many third-party security measures inactive.
Intrusion Tactics and Initial Access
The attack commenced with a credential-spraying offensive aimed at an exposed SonicWall SSL VPN lacking multi-factor authentication. Successful access was achieved using valid credentials, enabling the attackers to penetrate the network via remote desktop connection, subsequently mapping the network and exfiltrating vital data.
This method mirrors the vulnerabilities reported in recent SonicWall VPN breaches, highlighting the need for robust security protocols. Once inside, attackers swiftly leveraged remote access infrastructure, identifying critical systems, stealing data, and attempting encryption within a short timeframe.
Exploiting Safe Mode for Security Evasion
Security researcher Huntress noted this as the first observed case of Akira utilizing Safe Mode to disable endpoint detection and response (EDR) tools. This approach is significant due to Akira’s notoriety as a leading ransomware operation in 2025, where even unsuccessful encryption attempts can lead to data extortion.
After breaching the system, the attackers accessed the domain controller via Remote Desktop Protocol, extracting user and system data from Active Directory. Subsequently, they archived network shares using WinRAR, uploading them to cloud storage in preparation for encryption.
Challenges and Implications for Security Teams
To facilitate remote control, the attackers installed AnyDesk as a service, modifying the Safe Mode registry list to ensure its operation post-reboot. Initiating Safe Mode with Networking at 06:29 UTC, they temporarily disabled key defenses like Microsoft Defender, maintaining control through the remote-access service.
This strategy, though not novel, poses new challenges for security teams who must now consider unexpected boot configurations as high-priority threats. Moreover, even when the encryption failed due to virtual-memory constraints, the attackers had already exfiltrated credentials and files, setting the stage for a potential double-extortion scenario.
Preventive Measures and Future Outlook
The incident underscores the importance of multifactor authentication for VPN accounts and the need for prompt credential rotation following a compromise. Security teams should also centralize logging and monitoring to detect unusual activity patterns, such as failed login bursts followed by successful access from the same source.
By deploying comprehensive endpoint coverage and heeding lessons from past ransomware activities, organizations can better defend against intrusions and mitigate the risk of data theft or encryption. As ransomware tactics evolve, proactive measures remain crucial in safeguarding network integrity.
