International Cyber Expo International Cyber Expo
  • About Us
Monday, 28 September, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Akira Ransomware Affiliate Rebooted Into Safe Mode to Dodge EDR and Broke Its Own Attack

by Guru Writer
August 13, 2026
in News
Akira Ransomware Affiliate Rebooted Into Safe Mode to Dodge EDR and Broke Its Own Attack
Share on FacebookShare on Twitter

An affiliate of the Akira ransomware operation attempted a novel technique to blind endpoint defences during a recent intrusion, rebooting a compromised server into Windows Safe Mode to knock out both an EDR agent and Microsoft Defender in one move, only for the same stripped-down environment to cause the ransomware payload itself to crash before it could encrypt any files.

The incident, disclosed in a technical write-up published by managed detection and response provider Huntress, marks the first time researchers have observed Akira affiliates using a Safe Mode reboot to sidestep security tooling, a tactic more commonly associated with older ransomware families such as Snatch and AvosLocker.

Akira has been one of the most active ransomware operations tracked by Huntress over the past year, and its affiliates typically follow a consistent playbook: break in through an internet-exposed VPN appliance, most often from SonicWall, move laterally to the domain controller, enumerate Active Directory, exfiltrate data, and detonate the encryptor within a matter of hours. This latest attack followed that pattern almost exactly, according to Huntress, but introduced a twist at the final stage.

Credential Spray, No MFA, and a Familiar Path to the Domain Controller

According to Huntress, the intrusion began in early August with a burst of failed login attempts against a SonicWall SSL VPN, consistent with a credential-spraying attack. Roughly seven minutes later, one attempt succeeded: a valid VPN account with no multi-factor authentication in place. Nearly two hours passed before the attacker took hands-on action, logging into the domain controller over RDP and running PowerShell commands to dump full property details on every user and computer in the Active Directory environment, reconnaissance Huntress says is a hallmark of Akira intrusions.

The attacker then moved to an application server, installed WinRAR to archive mapped file shares, and used the S3 transfer tool s5cmd to upload the staged data to a cloud storage bucket under their control, standard double-extortion tradecraft designed to give the attacker leverage even if a victim can recover from backups. AnyDesk, a legitimate remote access tool, was installed as a persistent service and used both for hands-on-keyboard control and to deliver the ransomware payload itself.

The Safe Mode Gambit

Rather than spinning up a separate virtual machine to run the encryptor outside the reach of security software — a method Huntress has documented in earlier Akira cases- the affiliate instead used the built-in Windows configuration tool msconfig.exe to force the host to reboot into Safe Mode with Networking. Because Safe Mode loads only core Windows drivers and disables most third-party software by design, the reboot simultaneously took the Huntress agent offline and prevented Microsoft Defender’s real-time protection from starting, all while preserving the network connectivity the attacker needed to keep working.

The attacker had anticipated that Safe Mode would also block their own AnyDesk service, and pre-emptively added a registry entry to keep it running through the reboot, a detail Huntress says shows deliberate planning rather than an improvised move.

The Ransomware Undermined Itself

The plan worked well enough to blind defences, but it also appears to have doomed the attack. Minutes after the akira.exe payload launched, the host began throwing “out of virtual memory” errors, and the ransomware process tree failed before encryption could begin. Huntress attributes the crash to Safe Mode’s constrained memory environment, which was seemingly unable to support the ransomware’s resource demands.

A scheduled Defender scan eventually flagged the payload roughly an hour later, correctly identifying it as Akira, but could not quarantine it because real-time protection remained disabled in Safe Mode. The file was only removed after the attacker rebooted the host back into normal operation, restoring Defender’s protection in the process, meaning the attacker’s own anti-EDR trick was undone by their need to reverse it.

Despite the failed encryption, the attacker had already exfiltrated Active Directory data and file shares before the reboot, leaving the victim exposed to extortion even without any files being locked. Huntress cautioned that the outcome should not be read as a reliable defence: a host with more memory or a larger page file might allow the encryptor to succeed in Safe Mode, and researchers said it is plausible Akira’s developers will adjust the malware’s memory footprint or boot sequence to make the technique more reliable in future attacks.

Recommendations

Huntress urged organisations to enforce MFA on all VPN accounts, monitor for bursts of failed VPN logins followed by a successful one, and ensure EDR is deployed across every endpoint rather than a subset of the environment. It also recommended that defenders specifically alert on boot-configuration changes and Safe Mode reboots, including msconfig.exe and bcdedit activity, and Windows event log entries indicating a Safe Mode boot as well as any modification to the registry keys that control which services are permitted to run in Safe Mode.

ShareTweet
Previous Post

Is AI entering the SOC at the right stage?

Next Post

Scammers Exploit Shopify’s Own Notification System in New ‘Fake Refund’ Scam

Recent News

cyber threat intelligence

New Guide from Filigran Highlights the Many Routes Women Take into Cyber Threat Intelligence

September 28, 2026
James Moore, CultureAI Q&A: AI Security And Governance: Why Most Organisations Are Flying Blind

James Moore, CultureAI Q&A: AI Security And Governance: Why Most Organisations Are Flying Blind

September 28, 2026
Attackers build “silent” cryptominer on victim’s machine and give themselves away

Attackers build “silent” cryptominer on victim’s machine and give themselves away

September 25, 2026
OpenAI agent breached Australia’s Medicare portal – and nobody noticed for three months

OpenAI agent breached Australia’s Medicare portal – and nobody noticed for three months

September 25, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol