Scworld
Akira Ransomware Uses Safe Mode Reboot to Evade Detection
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
In early August 2026, an Akira ransomware attack utilized a Safe Mode reboot to bypass endpoint detection and response (EDR) systems. The attack began with unauthorized access through an exposed SonicWall SSL VPN lacking multi-factor authentication (MFA). After multiple failed login attempts, the attacker successfully accessed the domain controller via Remote Desktop Protocol (RDP). The attack followed a typical pattern, including Active Directory enumeration and file exfiltration using WinRAR and the s5cmd tool. Notably, the attacker rebooted the compromised host into Safe Mode with Networking, disabling third-party security products. Although the ransomware payload was transferred, file encryption failed due to insufficient virtual memory. Windows Defender later detected the ransomware during a scheduled scan, but the system could not automatically remediate the threat while in Safe Mode. This incident marks a new tactic for Akira, which has been previously documented in other ransomware operations.
Key Points: • Akira ransomware exploited an exposed SonicWall SSL VPN for initial access. • The attacker rebooted the compromised host into Safe Mode to evade EDR detection. • File encryption failed due to insufficient virtual memory during the attack.