← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Akira Ransomware Affiliate Bypasses EDR by Booting into Safe Mode, Steals Data

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Akira affiliate used Safe Mode with Networking to disable EDR and antivirus.
  • Initial access gained via an exposed SonicWall VPN without MFA.
  • Attackers stole data but failed to encrypt files due to system errors.
  • This tactic has been used by other ransomware families like Snatch and AvosLocker.

EDR Bypass via Safe Mode

An Akira ransomware affiliate bypassed endpoint detection and response (EDR) solutions by rebooting a compromised system into Safe Mode with Networking. This action disabled both the Huntress agent and Microsoft Defender's real-time protection for approximately 10 minutes, creating a window for malicious activity without detection.

Attack Progression and Data Exfiltration

The attack began on August 4, with initial access obtained through an exposed SonicWall VPN device lacking multi-factor authentication (MFA). After gaining access, the attacker connected to the domain controller, enumerated Active Directory, and moved to an application server. They used WinRAR to archive mapped file shares and s5cmd to upload stolen data to an S3 bucket, then installed AnyDesk for remote access. The attackers then used AnyDesk to force the system into Safe Mode with Networking.

Ransomware Payload Failure

While in Safe Mode, the attackers added AnyDesk to the Windows Safe Mode registry to maintain remote access. However, their attempt to launch the Akira ransomware payload (akira.exe) failed. The system reported low virtual memory and generated out-of-memory and PowerShell errors, preventing the encryption of files. Microsoft Defender, despite its real-time protection being disabled, eventually detected the Akira executable during a scheduled scan, but could only quarantine it after the system was rebooted into normal mode, restoring real-time protection.

Impact and Recommendations

Despite the failure to encrypt files, the Akira operator successfully stole credentials and files for data extortion within five hours of initial access. Huntress noted that this tactic of using Safe Mode to disable security tools has been observed with other ransomware families like Snatch and AvosLocker, but this is the first time it has been seen in an Akira attack. Researchers recommend implementing MFA for all VPN accounts and deploying credential-spraying detection measures to mitigate similar threats.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

An Akira ransomware affiliate disabled endpoint detection and response (EDR) by restarting a compromised system into Safe Mode with Networking, allowing data exfiltration. Although the ransomware payload failed to execute due to low virtual memory, the attackers successfully stole credentials and files. This incident highlights a known tactic, previously seen with other ransomware families, now observed in an Akira attack.