logo

Akira Ransomware Uses Safe Mode to Bypass EDR

ID: 7809424e-e04b-5d0a-962a-7b0f2c12b437

STIX ID: report--7809424e-e04b-5d0a-962a-7b0f2c12b437

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-08-17

Date Updated: 2026-08-17

Author: Pierluigi Paganini

...
...

Akira ransomware operators gained access via an MFA-less SonicWall VPN, exfiltrated data (Active Directory and mapped shares), then rebooted a compromised host into Safe Mode with Networking and added AnyDesk to the Safe Mode registry to disable EDR and maintain access; the Akira encryptor failed seconds after launching due to out-of-virtual-memory errors in the constrained Safe Mode environment, but the attacker’s exfiltration still enables extortion. Detection guidance highlights monitoring for bcdedit/msconfig use, Kernel Boot/General event IDs indicating Safe Mode, third-party service stops, and remote-access tools added to Safe Mode registry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.