Akira Ransomware forces victim devices into Safe Mode to evade Security detection | #ransomware | #cybercrime


The Akira ransomware group appears to have adopted a more sophisticated technique to evade endpoint security defenses and maintain access to compromised systems. According to research from Huntress, attackers associated with the Akira ransomware operation attempted to interfere with antivirus and endpoint security software before beginning their encryption activities. However, these attempts did not always go as planned. In some observed incidents, security tools detected the malicious activity and responded by quarantining the ransomware.

To overcome this obstacle, the attackers reportedly used a different approach: forcing compromised Windows systems to reboot into Safe Mode. Safe Mode is a Windows diagnostic environment that starts the operating system with a limited set of drivers, services, and startup applications. It is primarily intended for troubleshooting system problems, but attackers can potentially abuse this restricted environment to cutting down the number of security controls operating on a machine.

The technique is particularly concerning because many endpoint security products depend on system services, drivers, and other components that may not operate in the same manner during a Safe Mode session. By manipulating the system’s boot configuration and restarting the device, ransomware operators can attempt to create an environment in which their malicious processes face fewer active defenses.

Once the system has entered Safe Mode, Akira operators can attempt to execute their ransomware payload and begin encrypting files. The reduced operating environment may provide attackers with a temporary opportunity to interfere with security mechanisms, access locally stored data, and perform other stages of their attack before defenders can restore normal system operation.

However, the technique is not necessarily a guaranteed method of bypassing security software. Security products can employ multiple layers of protection, including behavioral monitoring, tamper protection, offline detection mechanisms, and other controls that can identify suspicious changes to boot configurations or ransomware-like activity. This explains why the Akira ransomware group’s attempts have resulted in both successful intrusion activity and detection or quarantine in observed cases.

The use of Safe Mode demonstrates how modern ransomware operations are increasingly focused on defense evasion, rather than simply delivering an encryption payload. Attackers continuously modify their techniques when conventional approaches, such as disabling antivirus software directly, trigger security alerts.

For organizations, this development highlights the importance of monitoring unexpected changes to Windows boot configuration, unauthorized system reboots, attempts to disable security services, and unusual file-encryption activity. Endpoint protection should also be configured with tamper-resistant controls wherever possible.

Akira’s Safe Mode technique therefore represents another evolution in ransomware tradecraft: instead of confronting security software directly, attackers attempt to alter the operating environment itself. Although this approach can provide ransomware operators with an advantage, effective endpoint monitoring and layered security controls can still disrupt the attack before widespread encryption occurs.

Join our LinkedIn group Information Security Community!



Click Here For The Original Source.

——————————————————–

..........

.

.