logo

Akira Hits Safe Mode: Ransomware Rebooting Around EDR

ID: d00066dc-f911-5043-bb71-ec9b4269dda2

STIX ID: report--d00066dc-f911-5043-bb71-ec9b4269dda2

Feed Name: Huntress Blog

Threat Score
78/100

Date Published: 2026-08-12

Date Updated: 2026-08-19

...
...

This report documents an August 2026 Akira ransomware intrusion that gained initial access through a credential-sprayed SonicWall SSL VPN lacking MFA, performed full Active Directory dumps, archived file shares with WinRAR, exfiltrated data using s5cmd to an attacker S3 bucket, and deployed akira.exe via an AnyDesk session; the operator rebooted a host into Safe Mode with Networking to disable third-party EDR/AV, which blinded defenses but caused the ransomware to fail due to virtual memory errors—reporting includes timeline, IOCs (IP, hostnames, binary/hash, AnyDesk ID), and concrete mitigations (MFA, EDR coverage, SIEM, Safe Mode monitoring).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.