
Unknown Organization Ransomware: Akira Affiliate Disables EDR, Data Stolen but No Encryption (June 2024)
Unknown Organization: What Happened
An Akira ransomware affiliate successfully infiltrated the network of an unknown organization by exploiting an exposed SonicWall VPN device that lacked multi-factor authentication (MFA). Within five hours, the attacker moved laterally using Remote Desktop Protocol (RDP), disabled endpoint detection and response (EDR) tools by rebooting systems into Safe Mode with Networking, and leveraged AnyDesk for remote access. During this window, the adversary exfiltrated sensitive data and credentials. Although the ransomware payload was deployed, it failed to execute encryption, sparing the organization from immediate operational disruption, but not from data compromise.
Attack Vector & Technical Detail
Initial access was achieved through an internet-exposed SonicWall VPN device without MFA, a critical misconfiguration that enabled the attacker to bypass perimeter defenses. The adversary used RDP for lateral movement, consistent with MITRE tactics TA0006 (Credential Access), TA0007 (Discovery), and TA0009 (Collection). To neutralize endpoint security, the attacker rebooted endpoints into Safe Mode with Networking, a state in which most EDR and Microsoft Defender protections are inactive, and installed AnyDesk for persistent remote access. No CVEs or specific IOCs were provided in the incident data, but the attack methodology aligns with recent Akira affiliate tradecraft. The operation was completed rapidly, with data and credential theft occurring before the failed encryption attempt.
Confirmed Impact
The breach resulted in the theft of sensitive organizational data and credentials, creating significant extortion and reputational risks for the affected entity. While the ransomware payload did not encrypt files, the temporary disabling of endpoint security tools left the environment exposed to further compromise. The incident is globally relevant, as SonicWall VPN devices are widely deployed and similar attack paths have been observed across multiple sectors. Regulatory exposure may arise from the unauthorized exfiltration of personal or confidential information, depending on the organization's jurisdiction and data type involved.
What This Means for Your Organization
This incident highlights the ongoing risk posed by exposed remote access infrastructure, particularly VPN devices lacking MFA. Organizations should immediately review remote access configurations to ensure MFA is enforced and unnecessary exposure is remediated. The use of Safe Mode to bypass EDR underscores the need for layered defenses, including tamper protection and monitoring for atypical reboots or remote access tool installations. Rapid detection and containment are critical, as attackers can achieve their objectives—including data theft—within hours of initial access.
Detection & Response
- Immediate: Audit all VPN endpoints for MFA enforcement and disable any unnecessary remote access services.
- Hunt: Investigate for evidence of Safe Mode reboots, unexpected AnyDesk installations, and unusual RDP activity within the environment.
- Patch: N/A (no CVE specified in this incident).
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

