Akira Ransomware Uses Safe Mode Reboot to Evade Detection

Akira Ransomware Uses Safe Mode Reboot to Evade Detection

First seen 12 Aug 2026, 23:33 UTC Huntressattack.mitre.orgwww.sophos.comScworld 86% similarity 51.9

Article Content

Browse articles
ThreatCluster

In early August 2026, an Akira ransomware attack utilized a Safe Mode reboot to bypass endpoint detection and response (EDR) systems. The attack began with unauthorized access through an exposed SonicWall SSL VPN lacking multi-factor authentication (MFA). After multiple failed login attempts, the attacker successfully accessed the domain controller via Remote Desktop Protocol (RDP). The attack followed a typical pattern, including Active Directory enumeration and file exfiltration using WinRAR and the s5cmd tool. Notably, the attacker rebooted the compromised host into Safe Mode with Networking, disabling third-party security products. Although the ransomware payload was transferred, file encryption failed due to insufficient virtual memory. Windows Defender later detected the ransomware during a scheduled scan, but the system could not automatically remediate the threat while in Safe Mode. This incident marks a new tactic for Akira, which has been previously documented in other ransomware operations.

Key Points: • Akira ransomware exploited an exposed SonicWall SSL VPN for initial access. • The attacker rebooted the compromised host into Safe Mode to evade EDR detection. • File encryption failed due to insufficient virtual memory during the attack.

ThreatCluster AI How this analysis works

Timeline

2026-08-04
Initial access via SonicWall SSL VPN
The attacker conducted multiple failed login attempts before successfully logging in without MFA protection.
Huntress
2026-08-04
Accessed domain controller via RDP
The attacker gained hands-on access to the domain controller approximately two hours after the successful VPN login.
Huntress
2026-08-04
Rebooted into Safe Mode with Networking
The attacker rebooted the host using msconfig.exe, disabling EDR services and allowing continued access.
Scworld
2026-08-04
Ransomware payload transferred
The akira.exe payload was transferred through AnyDesk before the Safe Mode reboot, but encryption failed due to insufficient memory.
Scworld
2026-08-04
Windows Defender detected ransomware
Detection occurred during a scheduled scan after the attacker rebooted the system normally, allowing remediation.
Scworld

Community

Browse all →