Scworld Akira Ransomware Uses Safe Mode to Evade EDR Detection
Article Content
- •Akira ransomware affiliates exploited an exposed SonicWall SSL VPN for initial access.
- •The use of Safe Mode allowed the attacker to disable EDR tools, but also led to ransomware failure.
- •This incident underscores the evolving tactics of ransomware groups to evade detection.
In early August 2026, an Akira ransomware affiliate executed an attack leveraging Safe Mode to evade endpoint detection and response (EDR) tools. The attack began with credential spraying against an exposed SonicWall SSL VPN lacking multi-factor authentication (MFA), leading to unauthorized access to the domain controller via Remote Desktop Protocol (RDP). The attacker performed Active Directory enumeration and collected sensitive files, transferring them to cloud storage using s5cmd. Uniquely, the attacker rebooted the compromised system into Safe Mode with Networking to disable security tools, including Huntress and Windows Defender. However, this tactic backfired, as it caused the ransomware payload to fail due to insufficient virtual memory. Although the attack did not result in file encryption, it highlighted a significant tactic used by ransomware groups to bypass security measures. Future attacks may not be as fortunate if the attackers adjust their methods to ensure successful encryption in Safe Mode.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (11)
Following this threat?
Track Akira, MDeployer and Sonicwall in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts…
Surge in Ransomware Attacks Targeting Manufacturing Sector in 2026 In 2026, ransomware attacks on the manufacturing sector surged nearly 40% year over year, with significant incidents including the Jaguar Land Rover attack that halted production for over five weeks. The Bank of England reported that this attack contributed to a 27% decline in UK car production in September 2025…