In brief: An Akira attacker disabled EDR and Defender via Windows Safe Mode, escaping with stolen data and credentials despite failed encryption – the entire attack took under five hours.
An Akira ransomware affiliate successfully disabled EDR software and Microsoft Defender real-time protection via Windows Safe Mode – however, the actual encryption failed due to a technical error, according to Huntress.
According to managed detection and response specialist Huntress, an attacker first gained access to the network on August 4 via an exposed SonicWall VPN device without multi-factor authentication. Roughly two hours after the VPN login, the attacker connected to the domain controller via RDP, enumerated users and machines in Active Directory, and pivoted to an application server. Using WinRAR, they archived shared file shares and uploaded the data to an S3 storage bucket under their control via the command-line tool s5cmd, before additionally installing the remote access software AnyDesk.
Via AnyDesk, the attacker then forced the compromised machine to reboot into Safe Mode with Networking and used this to disable both the Huntress agent and Microsoft Defender’s real-time protection. Safe Mode is intended for diagnostic and troubleshooting purposes and starts Windows with only a limited set of drivers and services, meaning most third-party programs never load in the first place. According to Huntress, the system “had no functioning EDR solution and its antivirus was blind for ten minutes while the system sat in Safe Mode.” To secure access across a reboot, the attacker also added AnyDesk to the Windows registry section responsible for Safe Mode.
The subsequent attempt to execute the ransomware file akira.exe via AnyDesk in Safe Mode failed: the system reported insufficient virtual memory and generated corresponding error messages as well as PowerShell errors. A regular, scheduled Microsoft Defender scan did detect the Akira file even in Safe Mode despite real-time protection being disabled, but was unable to remove it. Only after returning to normal mode and the associated reactivation of real-time protection did Defender quarantine the file.
Despite the failed encryption, the Akira affiliate nonetheless succeeded in stealing credentials and files for subsequent extortion. From the first login to the data theft, the attackers needed less than five hours. According to Huntress, ransomware families such as Snatch and AvosLocker have been using this technique for years already, but for Akira this is the first case the company has observed.
Huntress recommends that organizations set up multi-factor authentication for all VPN accounts, implement detection mechanisms against the systematic testing of stolen credentials, and specifically monitor for changes to the Safe Mode boot configuration and newly registered remote access tools in the registry.
Source: www.it-daily.net · Published August 17, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.