Akira Ransomware Abuses Safe Mode for EDR Evasion
Score: 8/10

Akira Ransomware Abuses Safe Mode for EDR Evasion

An Akira ransomware affiliate targeted a SonicWall VPN to exfiltrate data and attempted to bypass security controls by rebooting the victim host into Safe Mode.

Executive Summary

In early August 2026, threat intelligence researchers observed a novel tactic from an Akira ransomware affiliate who utilized Windows Safe Mode with Networking to disable security products. The attack began with a credential spray against a SonicWall SSL VPN lacking multi-factor authentication (MFA), followed by rapid domain enumeration and the exfiltration of sensitive file shares to an S3 bucket.

Technically, the actor modified the registry to ensure their AnyDesk remote access tool would persist in Safe Mode and used `msconfig.exe` to force a reboot. This temporarily blinded the Huntress agent and disabled Windows Defender's real-time protection. Notably, the ransomware payload failed to encrypt the system due to virtual memory exhaustion in the restricted Safe Mode environment; however, the attacker successfully exfiltrated data for potential double-extortion.

This marks an evolution in Akira tradecraft, adopting techniques previously seen in Snatch and AvosLocker campaigns. Organizations should prioritize MFA for VPNs and monitor for unauthorized boot configuration changes that signal EDR evasion attempts.

Key Details

Threat Name

Akira Ransomware

Affects

—

Adversary

Akira Other Adversaries and Aliases: Snatch; AvosLocker

Malware/Tools

Akira, AnyDesk, s5cmd, Snatch, AvosLocker

Report Score

8out of 10
Quality Score
Good
IOC Quality8
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure9
Technical Depth8

Sources