Akira ransomware scum blocked victim’s security tools – and broke their own encryptor

← Back to the feed

Akira ransomware scum blocked victim’s security tools – and broke their own encryptor

The Register · 3 hours ago

An affiliate of the Akira ransomware group compromised an organisation through a SonicWall SSL VPN account without multi-factor authentication, then tried to disable security software by restarting a machine in Safe Mode with Networking. The move prevented most third-party protections from running, but also caused the attacker’s ransomware encryptor to fail, avoiding file encryption on that endpoint. However, the incident still involved credential theft, network reconnaissance and data theft, showing that disrupted encryption does not eliminate the wider harm of a ransomware intrusion.

The intrusion began on 4 August with a credential-spraying attempt, followed seven minutes later by a successful login using a valid unprotected VPN account. The attacker used RDP to access the domain controller and collect detailed Active Directory information, then used WinRAR to archive file shares and s5cmd to transfer data to cloud storage; AnyDesk was installed for persistent remote access. Huntress said the encryption failure was probably related to memory configuration and warned that systems with more memory or a larger page file could allow Akira to work in Safe Mode in future.

  • Safe Mode stopped Akira’s encryptor, but data had already been stolen.
  • An unprotected VPN account enabled the intrusion.
  • MFA remains a key defence against credential-based ransomware attacks.

Business Crypto Cybersecurity Technology

Read the full article at the source →