2w ago · bleeping-computer
An Akira ransomware affiliate gained initial access via an exposed SonicWall VPN without MFA, then used RDP to move laterally and exfiltrate data. The attacker rebooted the compromised host into Safe Mode with Networking to disable EDR and AV solutions, including the Huntress agent and Microsoft Defender. Data was stolen using s5cmd and uploaded to an attacker-controlled S3 bucket, while AnyDesk was installed and configured to persist in Safe Mode. The ransomware payload (akira.exe) failed to execute due to low virtual memory, preventing encryption. Despite the failure, the actor exfiltrated sensitive data within five hours.