Skip to content

Akira Ransomware Disables EDR via Windows Safe Mode

In brief: An Akira attacker disabled EDR and Defender for ten minutes via Windows Safe Mode and stole data in under five hours, even though the encryption itself failed.

An Akira affiliate bypassed EDR and antivirus solutions by forcing a reboot into Windows Safe Mode. While the actual encryption failed due to a memory error, the theft of credentials and files still succeeded.

<p>According to the managed detection and response company Huntress, an Akira ransomware affiliate gained access to a corporate network on August 4 via an exposed SonicWall VPN appliance that was not protected by multi-factor authentication. Roughly two hours after the VPN login, the attacker connected to the domain controller via RDP, enumerated users and machines in Active Directory, and then moved laterally to an application server. Using WinRAR, they archived file shares and uploaded the data to a self-controlled S3 storage bucket via the command-line tool s5cmd, before additionally installing the remote access software AnyDesk.</p>

<p>Via AnyDesk, the attacker then forced a reboot of the compromised machine into Safe Mode with Networking and used it to disable both the Huntress agent and Microsoft Defender’s real-time protection. Safe Mode is designed to load only a limited set of drivers and services, which means most third-party programs fail to start in the first place. According to Huntress, the system had no functioning EDR solution for ten minutes, during which the antivirus was blind. To ensure access persisted even after a further reboot, the attacker also added AnyDesk to the Windows registry key responsible for Safe Mode.</p>

<p>The subsequent attempt to execute the ransomware file akira.exe via AnyDesk in Safe Mode failed due to insufficient virtual memory, with the system generating corresponding error messages and PowerShell errors. A regular, scheduled Microsoft Defender scan detected the Akira file even in Safe Mode despite real-time protection being disabled, but was unable to remove it there. Only after returning to normal mode, and the associated reactivation of real-time protection, did Defender quarantine the file.</p>

<p>Despite the failed encryption, the attacker succeeded in stealing credentials and files for subsequent extortion. Less than five hours elapsed between the initial login and the data theft. Huntress notes that other ransomware families such as Snatch and AvosLocker have been using this technique for years, but that this is the first observed instance of it in an Akira attack for the company.</p>

<p>This yields concrete action items for CISOs: Huntress recommends consistently securing all VPN accounts with multi-factor authentication, implementing detection mechanisms against the systematic testing of stolen credentials, and specifically monitoring changes to the Safe Mode boot configuration as well as remote access tools newly registered there. Since Safe Mode can systematically bypass common EDR agents, detection rules for reboots into this mode and associated registry changes should be a fixed part of monitoring.</p>


Source: www.it-daily.net · Published August 17, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: