Akira Hits Safe Mode: Ransomware Rebooting Around EDR
Cybersecurity Classified by Officially
After gaining access via an exposed SonicWall VPN, an Akira affiliate rebooted the victim host into Safe Mode with Networking to defeat EDR, a first for this ransomware variant in our telemetry.
Safe Mode is a boot mode that only loads essential drivers and services, disabling most third-party software. As such, the reboot stopped the Huntress agent and disabled Microsoft Defender's real-time protection; Defender couldn't quarantine the file until the attacker rebooted back to normal mode. Ransomware families like Snatch and AvosLocker have abused Safe Mode for years, but this is the first reported tie to Akira that Huntress has observed.
In this incident, Safe Mode also broke the ransomware. In its stripped-down memory environment, the Akira process tree hit an out-of-virtual-memory failure seconds after launching.
While the anti-EDR effort backfired and the ransomware did not deploy, the attacker had already exfiltrated credentials and file shares. Even without encrypting anything, they can still extort the victim by threatening to leak the stolen information.
Acknowledgments: Special thanks to Dray Agha for his help in analysing this attack.
Akira has become one of the most prolific ransomware operations and was the most active group we observed in 2025. Its affiliates have settled into a well-worn playbook: get in through an exposed VPN (usually SonicWall), pivot to the domain controller, enumerate Active Directory, stage and exfiltrate data, then detonate all within a few hours. Huntress has documented that playbook in depth: from the active exploitation of SonicWall SSL VPN appliances as an initial-access vector, to a recent case where an affiliate spun up a brand-new virtual machine on the victim's hypervisor specifically to run the encryptor somewhere Huntress wasn't installed.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.huntress.com/blog/akira-hits-safe-mode-ransomware-rebooting-around-edr
Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Huntress — imported from official source
- Official source
- https://www.huntress.com/blog/rss.xml RSS
- Imported
- September 20, 2026 19:55
- Versions
- 1 recorded
- Identity
https://www.huntress.com/blog/akira-hits-safe-mode-ransomware-rebooting-around-edr