💻
Akira ransomware sabotaged its own attack — and still walked away with stolen data
💻 Technology

Akira ransomware sabotaged its own attack — and still walked away with stolen data

The Akira ransomware gang attempted to reboot a victim's machine in Safe Mode to bypass security tools and deploy its encryptor, but accidentally broke the encryption payload in the process. A security defender later detected and quarantined the damaged payload, preventing file encryption. However, the attackers had already exfiltrated sensitive data before the self-inflicted failure. Security firm Huntress recommends VPN brute-force alerts, multi-factor authentication, SIEM logging and Safe Mode monitoring to counter Akira's tactics.

Comments

No comments yet