Skip to content
Akira Ransomware Uses Safe Mode to Evade EDR Detection

Akira Ransomware Uses Safe Mode to Evade EDR Detection

First seen 12 Aug 2026, 23:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 13, 2026 at 23:13 UTC
  • •Akira ransomware affiliates exploited an exposed SonicWall SSL VPN for initial access.
  • •The use of Safe Mode allowed the attacker to disable EDR tools, but also led to ransomware failure.
  • •This incident underscores the evolving tactics of ransomware groups to evade detection.

In early August 2026, an Akira ransomware affiliate executed an attack leveraging Safe Mode to evade endpoint detection and response (EDR) tools. The attack began with credential spraying against an exposed SonicWall SSL VPN lacking multi-factor authentication (MFA), leading to unauthorized access to the domain controller via Remote Desktop Protocol (RDP). The attacker performed Active Directory enumeration and collected sensitive files, transferring them to cloud storage using s5cmd. Uniquely, the attacker rebooted the compromised system into Safe Mode with Networking to disable security tools, including Huntress and Windows Defender. However, this tactic backfired, as it caused the ransomware payload to fail due to insufficient virtual memory. Although the attack did not result in file encryption, it highlighted a significant tactic used by ransomware groups to bypass security measures. Future attacks may not be as fortunate if the attackers adjust their methods to ensure successful encryption in Safe Mode.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 48d ago How this analysis works

Timeline

2026-08-04
Credential spraying attack initiated
The attacker attempted multiple logins on an exposed SonicWall SSL VPN, succeeding after several failed attempts.
Huntress
2026-08-04
Access to domain controller achieved
The attacker accessed the domain controller via RDP two hours after the successful VPN login.
Scworld
2026-08-04
System rebooted into Safe Mode
The attacker rebooted the compromised system into Safe Mode with Networking to disable security tools before executing the ransomware payload.
Infosecurity-Magazine
2026-08-04
Ransomware payload execution failed
The ransomware failed to encrypt files due to insufficient virtual memory triggered by the Safe Mode environment.
Huntress

More articles in this cluster (11)

Following this threat?

Track Akira, MDeployer and Sonicwall in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed