Akira hackers reboot systems into Safe Mode to disable defenses

An Akira ransomware affiliate rebooted a compromised machine into Windows Safe Mode to disable security tools and steal data, cybersecurity firm Huntress reported.
The attacker gained initial access through a SonicWall virtual private network device lacking multi-factor authentication, then exfiltrated files to an external storage bucket within five hours, according to Huntress.
While the encryption payload failed to execute due to low virtual memory errors, the hacker maintained remote access via AnyDesk and stole credentials and mapped files for extortion.
Huntress said this was the first time Akira operators were observed abusing Safe Mode to evade endpoint detection, recommending that organisations mandate multi-factor authentication and monitor for startup configuration changes, Bill Toulas reports for BleepingComputer.