By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Akira Hackers Use Safe Mode to Disable EDR, Steal Data
An affiliate of the Akira ransomware group successfully bypassed security defenses on a compromised system by rebooting the machine into Safe Mode with Networking. This tactic allowed the attackers to disable the endpoint detection and response (EDR) solution, a critical component for monitoring and protecting against malicious activity. The attackers then proceeded to exfiltrate data from the victim's network. However, despite their successful evasion of security measures and data theft, the group ultimately failed in their primary objective of encrypting the stolen data for ransom. This operational detail was observed and reported by security researchers analyzing the incident. The specific EDR solution targeted was not publicly disclosed, but the method of disabling it highlights a known vulnerability in how some security software interacts with Windows' Safe Mode feature. Safe Mode is a diagnostic startup mode for Windows that starts the operating system with a minimal set of drivers and services. When combined with networking capabilities, it can allow attackers to gain a foothold and execute tools without the full suite of security software running. The Akira ransomware, known for its targeting of various sectors including healthcare, finance, and education, typically encrypts victim data and demands payment for its decryption. The group has been active since at least March 2023 and has been associated with significant data breaches. This particular incident, however, represents a partial success for the defenders, as the data, while stolen, was not rendered unusable through encryption. The failure to encrypt may have been due to several factors, including detection by security teams during the exfiltration phase, technical limitations encountered by the attackers, or a strategic decision to abandon the encryption attempt after data theft. The incident underscores the persistent threat posed by ransomware groups and their evolving tactics, techniques, and procedures (TTPs). It also emphasizes the importance of robust security configurations that can prevent or mitigate the abuse of system recovery features like Safe Mode. Security best practices often include measures to restrict booting into Safe Mode or to ensure that critical security agents remain active even in this diagnostic environment. The investigation into this specific compromise is ongoing, with researchers continuing to analyze the full scope of the attack and the potential impact on the victim organization. The incident serves as a cautionary tale for organizations to regularly review and update their security postures to counter sophisticated threats that exploit system functionalities.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.