Executive Summary
In early August 2026, threat intelligence researchers observed a novel tactic from an Akira ransomware affiliate who utilized Windows Safe Mode with Networking to disable security products. The attack began with a credential spray against a SonicWall SSL VPN lacking multi-factor authentication (MFA), followed by rapid domain enumeration and the exfiltration of sensitive file shares to an S3 bucket.
Technically, the actor modified the registry to ensure their AnyDesk remote access tool would persist in Safe Mode and used `msconfig.exe` to force a reboot. This temporarily blinded the Huntress agent and disabled Windows Defender's real-time protection. Notably, the ransomware payload failed to encrypt the system due to virtual memory exhaustion in the restricted Safe Mode environment; however, the attacker successfully exfiltrated data for potential double-extortion.
This marks an evolution in Akira tradecraft, adopting techniques previously seen in Snatch and AvosLocker campaigns. Organizations should prioritize MFA for VPNs and monitor for unauthorized boot configuration changes that signal EDR evasion attempts.
