First Akira Safe Mode attack disables endpoint detection and response but fails to encrypt, Huntress says
Huntress Labs Inc. said today that an Akira ransomware affiliate rebooted a victim’s Windows server into Safe Mode to knock its endpoint security offline — and it worked. The same reboot also broke the ransomware.
Safe Mode loads only core Windows drivers and services. Third-party security products sit outside that minimal set by design. That one reboot was enough to take the Huntress agent offline.
Microsoft Corp.’s Defender lost real-time protection at the same moment, and the “with Networking” variant kept the attacker connected through all of it. Snatch and AvosLocker have abused the technique, cataloged by MITRE as T1688, for years. Akira had not been seen using it until now, according to Huntress.
Entry came through a SonicWall Inc. SSL VPN on Aug. 4, with no multifactor authentication in front of it. The firewall began logging failed logins against multiple usernames from several external addresses at roughly 03:45 UTC, a straightforward credential spray. Seven minutes later a valid account got through. Akira affiliates have been working SonicWall SSL VPN appliances since that campaign surfaced last year, and Huntress has documented the playbook in detail.










