tech ๐ป Akira attack tricks system into safe mode ๐ฑ
A first Akira ransomware attack successfully rebooted a Windows server into Safe Mode, effectively disabling endpoint security tools like Huntress and Defender. This incident occurred on August 4th, originating from a SonicWall SSL VPN without multi-factor authentication. The attacker conducted extensive Active Directory enumeration and staged data before forcing a restart at 06:29:21 UTC. However, the stripped-down memory environment in Safe Mode appeared to starve the ransomware, preventing file encryption. Despite the failed encryption, the victim was still threatened with extortion as credentials and data had already left the network.