View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Akira affiliate rebooted Windows host into Safe Mode to evade EDR

๐Ÿšจ ACTIVE EXPLOITATION

  • Akira affiliate rebooted Windows host into Safe Mode to evade EDR An Akira affiliate used Windows Safe Mode to evade endpoint defenses.

    • Organizations using exposed SonicWall SSL VPNs and Windows endpoints were targeted.
    • Safe Mode disabled the Huntress agent and Microsoft Defender real-time protection.
    • The attacker used credential spraying, RDP, AnyDesk and msconfig.exe to reach and reboot the host.
    • The actor stole credentials and file shares with WinRAR and s5cmd before launching akira.exe; encryption failed from virtual-memory errors.
    • IOC: 72.23.77[.]35; akira.exe SHA-256 414b9985f46714f44dd1bd63860d2a48dcfababcfe5c712a4b4f575378127a56. ๐Ÿ“„ Source: huntress.com ยท ๐Ÿ“Ž Coverage: theregister.com ยท ๐Ÿ‘ via Cyber Security News, cryptika.com (discovered)
  • Phantom Stealer Hides Encrypted Payloads in PNGs to Steal Windows Data Phantom Stealer is stealing sensitive data from Windows users.

    • Windows users in multiple countries are targeted by .NET-based Phantom Stealer campaigns.
    • The malware steals browser passwords, cookies, payment-card data, cryptocurrency wallets, credentials, files, screenshots, keystrokes and clipboard contents.
    • Phishing emails, malicious links, pirated software and Discord or Telegram lures deliver the malware.
    • A .NET loader decrypts payloads hidden in PNG resources, while obfuscated PowerShell compiles C# and injects shellcode into explorer.exe.
    • Reported SHA-256 IOCs include b588caa5365451a6c60fd73fec5b73f13ac41bcc2a3a3bed7244df5917a62f32, 382233c398cbc35dcee845ee17046815f37588a382a8106bfb9b0252ea803961 and be119a21bedc3a79bf4dea8bcf5adf18304997a01ea23e276b9c31be37b789ab. ๐Ÿ“„ Source: splunk.com ยท ๐Ÿ“Ž Coverage: gbhackers.com ยท ๐Ÿ‘ via Cyber Security News, cryptika.com (discovered)

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • White House Authorizes Vetted Firms to Conduct Cyber Operations Against Foreign Gangs The White House has authorized vetted private firms to conduct government-supervised cyber operations against foreign criminal groups.

    • The program applies to vetted U.S. cybersecurity companies targeting foreign cyber-enabled transnational criminal organizations.
    • Targets include groups linked to ransomware, financial fraud and other crimes affecting Americans.
    • Companies may conduct cyber surveillance and cyber effects operations, including disruption, degradation or destruction of systems.
    • The DHS National Coordination Center will manage the program under DHS and DOJ oversight.
    • Participating firms may need a bond or escrow of at least $1 million. ๐Ÿ“„ Source: whitehouse.gov ยท ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via SecurityWeek, @campuscodi@mastodon.social (+4)
  • Jewelbug APT Conducts Espionage and Cryptocurrency Theft Jewelbug hackers-for-hire conducted both cyber espionage and cryptocurrency theft.

    • Jewelbug is a suspected advanced persistent threat group linked to hackers-for-hire.
    • The group conducted cyber espionage and financially motivated cryptocurrency heists.
    • Researchers observed both operations managed through the same web panel. ๐Ÿ“Ž Coverage: darkreading.com ยท ๐Ÿ‘ via Dark Reading
  • SpecterOps Blacklight Finds Sensitive AI Coding-Agent Artifacts SpecterOps released Blacklight to identify sensitive artifacts left by AI coding agents.

    • AI coding-agent users of Codex, Claude Code, Cursor, and Antigravity CLI are affected.
    • Local agent artifacts can expose authentication data, tokens, session history, project details, and connected services.
    • Blacklight is an open-source toolkit that discovers and analyzes these artifacts on endpoints. ๐Ÿ“„ Source: specterops.io ยท ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News, cryptika.com (discovered)
  • Imperva Finds Nearly 40% of APIs Have Multiple Authentication Risks Imperva found that nearly 40% of APIs have multiple authentication risks.

    • The report covers 1,104 customer environments and 32,725 live API endpoints.
    • The risks affect JWTs, Basic Authentication, and token lifecycles.
    • Measured issues include sensitive JWT data, weak signing algorithms, long token lifespans, raw Basic Auth credentials, and expired tokens retaining access.
    • Weak JWT signing algorithms appeared in 15.2% of detections, down from 19.0% year over year.
    • The findings are based on real API detection data across five authentication-risk categories. ๐Ÿ“Ž Coverage: imperva.com ยท ๐Ÿ‘ via Imperva

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check