
An Akira ransomware affiliate disabled the endpoint detection and response (EDR) answer on a compromised system by restarting the machine into Protected Mode with Networking.
The assault occurred on August 4 after the hacker obtained preliminary entry via an uncovered SonicWall VPN machine with out multi-factor authentication (MFA).
Managed detection and response (MDR) providers firm Huntress says that roughly two hours after a profitable VPN login, the attacker related to the area controller by way of RDP, enumerated Energetic Listing customers and computer systems, after which moved to an software server.
They used WinRAR to archive mapped file shares and the s5cmd command-line device to add the stolen knowledge to an attacker-controlled S3 bucket, earlier than putting in AnyDesk for distant entry.
At that stage, the attacker used AnyDesk to pressure the compromised host besides into Protected Mode with Networking and disable each the Huntress agent and Microsoft Defender’s real-time safety.
Protected Mode is a Home windows startup state designed for troubleshooting and diagnostic operations. It begins Home windows with a restricted set of drivers and providers, usually stopping most third-party software program and providers from loading.
For 10 minutes whereas in Protected Mode, “the host had no working EDR, and AV was blinded,” Huntress says.
In the meantime, the attackers added AnyDesk to Home windows’ Protected Mode registry, permitting it to start out after reboot and retain their distant entry to the breached machine.
Nevertheless, once they tried to launch the principle ransomware payload (akira.exe) by way of AnyDesk in Protected Mode, it didn’t execute because the system reported low digital reminiscence and generated out-of-memory and PowerShell errors.

Supply: Huntress
A scheduled Defender scan finally detected the Akira executable, even when real-time safety was disabled in Protected Mode, however the safety device couldn’t take away it whereas the machine remained in that mode.
Defender quarantined the file solely after the attacker rebooted the system into regular mode, which restored real-time safety.
Regardless of the failure to encrypt recordsdata, the Akira operator nonetheless managed to steal credentials and recordsdata for knowledge extortion, all in lower than 5 hours from preliminary entry.
Huntress notes that different ransomware households, equivalent to Snatch and AvosLocker, have used this tactic for years, however this incident marks the primary time the corporate noticed it in an Akira assault.
The researchers suggest including MFA to all VPN accounts, inserting credential-spraying detection measures, and monitoring for Protected Mode boot configuration modifications or remote-access instruments being added to the Protected Mode service registry.
General prevention scores can disguise what occurs after preliminary entry. As soon as attackers are utilizing legitimate credentials, prevention drops sharply.
The Blue Report 2026 measures defenses approach by approach throughout 338 million simulations run in buyer manufacturing environments.

