logo

Akira Affiliate Crashes Ransomware After Attempting EDR Evasion

ID: ad9234a1-fb8d-55be-bd14-bf9f5e5a21d2

STIX ID: report--ad9234a1-fb8d-55be-bd14-bf9f5e5a21d2

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-08-13

Date Updated: 2026-08-13

...
...

Huntress details an Akira ransomware affiliate intrusion where credential spraying against an unprotected SonicWall VPN led to RDP access, Active Directory enumeration, file theft (exfiltrated via s5cmd), and an attempted EDR-evasion by rebooting the host into Safe Mode; the Safe Mode boot blinded security agents but unexpectedly caused memory errors that prevented the ransomware from encrypting files. The post highlights this Safe Mode boot (MITRE T1688) as an EDR-impairing technique, warns that future variants could succeed, and provides detection and mitigation guidance including MFA, VPN hardening, monitoring for Safe Mode boot indicators, EDR deployment, and log ingestion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.