Akira ransomware disables EDR via Safe Mode, steals data but no encryption

An Akira ransomware affiliate bypassed endpoint detection by rebooting the infected system into Safe Mode with Networking to disable the EDR solution, stealing data without encrypting files.

Why it matters

This evasion method demonstrates how attackers can circumvent endpoint detection and response mechanisms by exploiting Safe Mode, complicating incident detection and response efforts.

SOC impact

Analyze endpoint telemetry for reboots into Safe Mode with Networking and monitor for unexpected EDR service interruptions. Investigate data exfiltration indicators while noting the absence of encryption activity.

Recommended actions

  1. Monitor for system reboots into Safe Mode with Networking on endpoints
  2. Review EDR service status and logs for unexpected disablement
  3. Investigate suspicious data access and exfiltration activities
  4. Correlate endpoint events with network telemetry for anomaly detection
  5. Assess affected hosts for signs of Akira ransomware activity

Executive Summary

Researchers have identified a new tactic used by an Akira ransomware affiliate that involves rebooting compromised systems into Safe Mode with Networking to disable endpoint detection and response (EDR) tools. This technique allows attackers to evade common security controls by operating in an environment where security software does not load.

Although the attackers successfully stole data during these incidents, they did not follow through with encrypting files, diverging from typical ransomware behavior. For defenders, this highlights a need to monitor systems for unusual Safe Mode usage and EDR service interruptions, as these can indicate active intrusions involving data theft attempts without encryption.

SOC Impact

Analyze endpoint telemetry for reboots into Safe Mode with Networking and monitor for unexpected EDR service interruptions. Investigate data exfiltration indicators while noting the absence of encryption activity.

Detection and Endpoint Validation

  • Monitor for system reboots into Safe Mode with Networking on endpoints
  • Review EDR service status and logs for unexpected disablement
  • Investigate suspicious data access and exfiltration activities
  • Correlate endpoint events with network telemetry for anomaly detection
  • Assess affected hosts for signs of Akira ransomware activity

Why It Matters

This evasion method demonstrates how attackers can circumvent endpoint detection and response mechanisms by exploiting Safe Mode, complicating incident detection and response efforts.

Source