• Ransomware gang crashes own attack with no-one to blame but them

    From TechnologyDaily@1337:1/100 to All on Mon Aug 17 17:30:23 2026
    Ransomware gang crashes own attack with no-one to blame but themselves

    Date:
    Mon, 17 Aug 2026 16:15:00 +0000

    Description:
    In a new attack, Akira disables EDR tools, but kills the encryptor, as well, as researchers still warn of a worrying practice.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Akira ransomware tried Safe
    Mode boot to disable defenses but broke its own encryptor Defender later flagged and quarantined payload, leaving attackers with only stolen data Huntress advises VPN bruteforce alerts, MFA, SIEM logging, and Safe Mode monitoring A recent ransomware attack saw the operators Akira (figuratively) shoot themselves in the foot - and they still walked away with sensitive
    data, albeit limping.

    Akira is a well-known ransomware group, considered one of the most active cybercriminal organizations on the internet. Its modus operandi is simple in theory: they look for an exposed VPN instance (for example, one with a
    default or weak password), access the domain controller, enumerate Active Directory, steal sensitive data, and deploy an encryptor. With the encryptor they leave a ransom note, instructing the victim to reach out and negotiate a payment in exchange for the decryption key and for deleting the stolen documents and information. Latest Videos From TechRadar Watch full video
    here:

    However, in a recent attack, they tried to first disable the devices
    antivirus and endpoint detection and response (EDR) solutions. The process backfired, resulting in the security solutions successfully spotting and quarantining the encryptor. The good and the bad of Safe Mode with Networking A new report published by security researchers Huntress said that after establishing persistence on a device, Akira rebooted it into Safe Mode with Networking. This Windows startup mode boots the OS with only the essential drivers and services, excluding important components such as antivirus programs or EDR agents. At the same time, it grants internet access which,
    for Akira, is the perfect combination. You may like Experts warn of the first documented case of 'agentic ransomware Sophos report warns new "WantToCry" ransomware could pose a major risk Reported ransomware incidents are just the tip of the iceberg

    This means Defender real-time protection was down too, Akira explained. For the entire Safe Mode window, the host had no working EDR, and AV was blinded. This is MITRE ATT&CK T1688: Impair Defenses: Safe Mode Boot, a technique that ransomware families like Snatch and AvosLocker have used for years. However, this is the first time we have seen Akira use it.

    What Akira didnt bank on was Safe Mode with Networking also preventing its encryptor from running. Safe Mode boots with a stripped-down environment and constrained virtual memory, and the Akira process tree appears to have
    starved it, getting the "Out of Virtual Memory" pop-up and the cascade of PowerShell hard errors line up exactly with the moment the payload tried to kick things off. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners
    or sponsors By submitting your information you agree to the Terms &
    Conditions and Privacy Policy and are aged 16 or over.

    The operators had no other choice but to boot the device back up normally, at which point a scheduled Defender scan detected the encryptor, flagged it, and ultimately quarantined it.

    The takeaway is a little uncomfortable. While Safe Mode blinded our controls, it may also have prevented the encryption it was meant to enable. That's a lucky side effect of the attacker's own mistake in these circumstances, not a defense you can plan around, Huntress warned, stressing that not every victim might get such a lucky break.

    Ultimately, this could be a case of winning the battle, but not the war. It's possible that a host with more physical memory or a larger page file might give akira.exe enough virtual memory to encrypt the endpoint in Safe Mode. Akira's developers or affiliates could retool the encryptor to reduce its memory demands or make its Safe Mode launch sequence more reliable, meaning that the same failure may not occur in a future intrusion. What to read next DeepSeek accidentally built a working ransomware strain Most ransomware attacks are opportunistic. Heres how you can stop attackers When trust
    becomes the attack surface How to defend against Akira ransomware To defend against Akira, Huntress recommends users set up alerts on bursts of failed
    VPN logins against multiple usernames from one source. It works well because Akira starts its breach with a brute-force attack against the VPN. It also says users should correlate those failures with a successful login from the same IP or ASN within a short window.

    The second step is to turn on multi-factor authentication ( MFA ) on every
    VPN account. Users should also disable or IP-allowlist the SSL VPN during active attacks and, if compromised, rotate all AD and VPN credentials. Treat everything in that Get-ADUser dump as exposed, the researchers warn.

    EDR should be deployed to every host, as well as SIEM and ingest VPN +
    Windows Event Logs. The first VPN logons were visible hours before any detonationthis time advantage is only possible if the logs are on SIEM.

    Finally, users can set up alerts on boot-configuration changes and Safe Mode boots, to catch Akira red handed. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/ransomware-gang-crashes-own-attack-with -no-one-to-blame-but-themselves


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)