SECURITY
SECURITY
SECURITY
Huntress Labs Inc. said today that an Akira ransomware affiliate rebooted a victim’s Windows server into Safe Mode to knock its endpoint security offline — and it worked. The same reboot also broke the ransomware.
Safe Mode loads only core Windows drivers and services. Third-party security products sit outside that minimal set by design. That one reboot was enough to take the Huntress agent offline.
Microsoft Corp.’s Defender lost real-time protection at the same moment, and the “with Networking” variant kept the attacker connected through all of it. Snatch and AvosLocker have abused the technique, cataloged by MITRE as T1688, for years. Akira had not been seen using it until now, according to Huntress.
Entry came through a SonicWall Inc. SSL VPN on Aug. 4, with no multifactor authentication in front of it. The firewall began logging failed logins against multiple usernames from several external addresses at roughly 03:45 UTC, a straightforward credential spray. Seven minutes later a valid account got through. Akira affiliates have been working SonicWall SSL VPN appliances since that campaign surfaced last year, and Huntress has documented the playbook in detail.
The login sat unused for almost two hours. The operator then came in over Remote Desktop Protocol on the domain controller, opened an elevated command prompt and pinged an internal address to check reachability. Active Directory enumeration followed. Get-ADUser and Get-ADComputer pulled every property on every account and every machine in the domain.
The output went to two text files under C:\ProgramData. A $formatenumerationlimit value of -1 in the script strips PowerShell’s four-item limit on multi-valued attributes such as MemberOf, so no group membership is left out. Huntress detections show the results being opened in Notepad.
Collection moved to an application server. The attacker downloaded and installed WinRAR mid-intrusion, then pointed it at four mapped file shares. Staged archives went out to an attacker-controlled S3 bucket using s5cmd, a fast transfer utility that Defender classifies as a hacking tool. The WinRAR flags match the ones Huntress logged in the earlier SonicWall campaign.
Before detonating anything, the operator installed AnyDesk as a service and added it to the Safe Boot registry key, keeping the remote-access channel alive through the reboot that was about to kill everything else.
At 06:29:21 UTC came msconfig.exe and a forced restart. The host returned with Kernel-Boot event 27 carrying a SAFEBOOT:NETWORK load option and Kernel-General event 12 showing BootMode 2. Defender logged error 0x8007043c seconds into the boot: “This service cannot be started in Safe Mode.”
AnyDesk came back with the host, as intended. The operator pushed a file across the session, and four blocks of pasted text moved through its clipboard, which points to hands-on typing rather than an unattended script. The akira.exe process tree started 27 seconds after that transfer finished, at 06:34:29 UTC. Reboot included, the whole session ran under 10 minutes.
Then the plan fell apart. The process tree spawned its child burst at 06:36:21 UTC. Seconds later, the host began logging “Virtual Memory Minimum Too Low,” then “Out of Virtual Memory,” then a PowerShell failure to create a new guard page for the stack. Safe Mode’s stripped-down memory environment appears to have starved it. Nothing was encrypted.
A scheduled Defender scan flagged the binary as Ransom:Win32/Akira.B!ibt at 07:43:50 UTC, but cleanup failed repeatedly with real-time protection dead. Quarantine succeeded at 08:12:28 UTC, roughly two minutes after the attacker rebooted back into normal Windows and restored the protection they had switched off.
“While Safe Mode blinded our controls, it may also have prevented the encryption it was meant to enable,” Huntress researcher James Northey wrote in a blog post. “That’s a lucky side effect of the attacker’s own mistake in these circumstances, not a defence you can plan around.”
The failure may not repeat. A host with more physical memory or a larger page file could hand the encryptor the room it needs, and Akira’s developers can trim the payload’s memory demands or make its Safe Mode launch sequence more reliable.
None of it saved the victim from extortion. Credentials and file share contents had already left the network before the reboot, which is enough to threaten a leak without encrypting a single file.
Huntress recommends multifactor authentication on every VPN account, alerts on failed-login bursts that resolve into a success from the same address or ASN, and EDR coverage on every host rather than a fraction of them. For this specific play, defenders should watch msconfig.exe and bcdedit activity, Kernel-Boot event 27 with a SAFEBOOT load option, third-party security services stopping under System event 7036, and anything new being added to the Safe Boot registry list.
Akira remains among the most prolific ransomware operations running. The group has collected about $244 million in proceeds as of September 2025, according to a joint advisory from the U.S. Cybersecurity and Infrastructure Security Agency and international partners updated in November, and its affiliates keep testing ways to put the encryptor somewhere defenders cannot see, including standing up a fresh virtual machine on a victim’s hypervisor.
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.