Akira Ransomware Disables EDR in Safe Mode Before Stealing Data
An Akira ransomware affiliate bypassed endpoint detection and response (EDR) protections by rebooting a compromised Windows system into Safe Mode with Networking. Although the attackers failed to encrypt files, they successfully stole credentials and exfiltrated data.
The attack began on August 4 after the threat actors gained initial access through exposed SonicWall VPN devices that did not require multi-factor authentication (MFA).
According to managed detection and response (MDR) provider Huntress, the attackers connected to the domain controller via Remote Desktop Protocol (RDP) approximately two hours after the successful VPN login. They then enumerated Active Directory users and computers before moving to an application server.
The threat actors used WinRAR to archive data from mapped network shares. They also used s5cmd, a command-line tool, to upload stolen files to an attacker-controlled Amazon S3 bucket before installing AnyDesk for remote access.
Using AnyDesk, the attackers forced the compromised host to restart in Safe Mode with Networking. This prevented the Huntress agent and Microsoft Defender real-time protection from loading normally.
Windows Safe Mode is a diagnostic startup environment that loads only a limited number of drivers and services. Because most third-party applications and security services do not run in this mode, attackers can use it to weaken endpoint defenses.
After approximately 10 minutes in Safe Mode, Huntress reported that the host no longer had active EDR protection and that antivirus defenses were effectively blind.
The attackers also added AnyDesk to the Windows Safe Mode registry, allowing the remote access software to launch after the reboot and preserve access to the compromised system.
However, the attack did not go entirely as planned. When the attackers attempted to launch the primary Akira ransomware payload, akira.exe, through AnyDesk in Safe Mode, execution failed because Windows reported insufficient virtual memory. The process also generated an out-of-memory error and a PowerShell error.

Source: Huntress
A scheduled Microsoft Defender scan eventually detected the Akira executable, even though real-time protection was disabled in Safe Mode. However, Defender could not remove the malware while the system remained in the restricted startup environment.
After the attackers restarted the computer in normal mode, Microsoft Defender’s real-time protection was restored and the security tool quarantined the malicious files.
Although Akira failed to encrypt the victim’s files, the operators stole credentials and sensitive data and completed exfiltration within five hours of gaining initial access.
Huntress said other ransomware groups, including Snatch and AvosLocker, have used Safe Mode to bypass security protections for years. However, this was the first Akira ransomware incident in which the company observed the tactic.
Security researchers recommend enabling MFA on all VPN accounts, deploying controls to detect credential theft and misuse, and monitoring changes to Safe Mode boot configurations. Organizations should also watch for remote access tools, such as AnyDesk, being added to the Windows Safe Mode service registry.
The overall prevention score can hide what happens after initial access. When attackers use valid credentials, the effectiveness of security defenses can drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com




