Back to all lessons
Awareness Lessons
2 months ago

Akira Ransomware Exploits Unpatched VPN and Safe Mode to Bypass EDR

An Akira ransomware affiliate gained initial access through an unpatched SonicWall VPN appliance — a critical failure in patch management that left a well-known attack vector wide open. Once inside, the attacker abused Safe Mode with Networking, a legitimate Windows feature, to disable endpoint detection tools like EDR and Microsoft Defender, demonstrating how configuration weaknesses can be weaponized. Although the ransomware payload failed to execute, the attacker still successfully exfiltrated sensitive data for double-extortion purposes, proving that encryption is no longer required for significant business harm. This incident highlights that patching internet-facing appliances and hardening endpoint configurations are non-negotiable baseline controls.

Tactical Insight

Immediate actions

  • Patch or upgrade all SonicWall VPN appliances (and other internet-facing devices) to the latest vendor-released firmware immediately.
  • Audit and restrict which accounts have the privileges required to reboot systems into Safe Mode.
  • Verify EDR solutions are configured to persist and remain active during Safe Mode boots where technically supported.

Long-term improvements

  • Implement a formal vulnerability management program that prioritizes internet-facing assets with a ≤72-hour SLA for critical CVEs.
  • Enforce network segmentation so that a compromised VPN endpoint cannot directly reach internal RDP services or sensitive data stores.
  • Deploy a privileged access management (PAM) solution to limit lateral movement via RDP and enforce just-in-time access.

Detection measures

  • Alert on unexpected Safe Mode reboots and boot configuration changes (e.g., `bcdedit` commands) via SIEM or endpoint telemetry.
  • Monitor for large outbound data transfers and use Data Loss Prevention (DLP) controls to detect and block exfiltration attempts.
  • Establish baseline RDP usage patterns and trigger alerts on anomalous lateral movement between hosts.