An Akira ransomware affiliate breached a network through an exposed SonicWall VPN without MFA, then moved laterally, stole data, and used AnyDesk plus Safe Mode with Networking to disable defenses. The ransomware payload failed to run, but the attacker still exfiltrated credentials and files for extortion in under five hours. #Akira #SonicWall #AnyDesk #Huntress
Keypoints
- The attacker gained access through an exposed SonicWall VPN device without MFA.
- They used RDP to reach the domain controller and enumerate Active Directory.
- WinRAR and s5cmd were used to archive and upload stolen data to an attacker-controlled S3 bucket.
- AnyDesk was installed and used to boot the host into Safe Mode with Networking and disable EDR and Microsoft Defender.
- The Akira payload failed to execute, but data theft and credential theft still succeeded.