Published Security3 min read
Akira Affiliate Booted a Host Into Safe Mode to Blind EDR, and Still Failed to Encrypt
A SonicWall VPN account without MFA, ten minutes of no EDR, and a ransomware binary that died of low virtual memory. Huntress says the data still left the building in under five hours.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- An Akira ransomware affiliate disabled the endpoint detection and response solution on a compromised system by restarting the machine into Safe Mode with Networking.
- The attack occurred on August 4 after the attacker obtained initial access through an exposed SonicWall VPN device without multi-factor authentication.
- Huntress says that roughly two hours after a successful VPN login, the attacker connected to the domain controller via RDP, enumerated Active Directory users and computers, and then moved to an application server.
- The attacker used WinRAR to archive mapped file shares and the s5cmd command-line tool to upload the stolen data to an attacker-controlled S3 bucket, before installing AnyDesk for remote access.
- The attacker used AnyDesk to force the compromised host to boot into Safe Mode with Networking and disable both the Huntress agent and Microsoft Defender's real-time protection.
Compiled by The WatchSomething wrong?How this is made
Why it matters
An Akira ransomware affiliate got into a network on August 4 through an exposed SonicWall VPN device that had no multi-factor authentication, then disabled the endpoint agents by rebooting the host into Safe Mode with Networking [1][2]. According to Huntress, the managed detection and response firm that investigated, the encryption stage failed but the data theft did not: credentials and files were gone in under five hours from initial access [3][12].
The sequence is worth reading as a clock. Roughly two hours after a successful VPN login, the attacker was on the domain controller over RDP, enumerating Active Directory users and computers, and then moved to an application server [3]. WinRAR archived mapped file shares, the s5cmd command line tool pushed the archives to an attacker-controlled S3 bucket, and AnyDesk went in for persistent remote access [4]. Everything after the VPN login used tools an administrator could plausibly own.
The control bypass came next. Using AnyDesk, the attacker forced the host to boot into Safe Mode with Networking and turned off both the Huntress agent and Microsoft Defender's real-time protection [5]. Safe Mode is a Windows diagnostic state that starts with a limited set of drivers and services and generally prevents most third-party software and services from loading, which is exactly why it works as an EDR kill switch [6]. Huntress says that for 10 minutes, "the host had no working EDR, and AV was blinded" [7]. To keep their access through the transition, the attackers added AnyDesk to the Safe Mode registry so it would start after the reboot [8].
Then the payload failed on its own. When akira.exe was launched via AnyDesk in Safe Mode, it did not execute: the system reported low virtual memory and threw out-of-memory and PowerShell errors [9]. A scheduled Defender scan later flagged the Akira executable even though real-time protection was off, but Defender could not remove it while the machine stayed in Safe Mode [10]. The file was quarantined only after the attacker rebooted into normal mode and restored real-time protection [11].
Two things follow for anyone running endpoint tooling. First, the blind window was short in absolute terms and short relative to the intrusion, about 3 percent of a sub-five-hour operation [15], but it was placed at the exact moment that mattered. Second, the technique beat the agents without beating the environment. A host rebooting into Safe Mode with Networking, a remote-access tool being written into the Safe Mode service registry, and a domain controller RDP session two hours after a first-time VPN login are all observable events that do not require a live agent on the box to notice [14][3]. Huntress recommends MFA on all VPN accounts, credential-spraying detection, and monitoring for Safe Mode boot configuration changes and remote-access tools added to the Safe Mode service registry [14].
This is not a new idea. Huntress notes that Snatch and AvosLocker have used the Safe Mode tactic for years, and says this is the first time the company has observed it in an Akira intrusion [13]. Treat it as adopted, not experimental.
What to watch: whether Akira affiliates keep the Safe Mode step now that it produced a botched encryption run, and whether the extortion proceeds on stolen data alone. The gap between the two hours to domain controller and the under five hours to completion leaves less than three hours for everything after the foothold [16], which is the realistic budget for anyone hoping to interrupt this pattern.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
An Akira ransomware affiliate disabled the endpoint detection and response solution on a compromised system by restarting the machine into Safe Mode with Networking.
- [2]
The attack occurred on August 4 after the attacker obtained initial access through an exposed SonicWall VPN device without multi-factor authentication.
ReportedView cited source - [3]
Huntress says that roughly two hours after a successful VPN login, the attacker connected to the domain controller via RDP, enumerated Active Directory users and computers, and then moved to an application server.
- [4]
The attacker used WinRAR to archive mapped file shares and the s5cmd command-line tool to upload the stolen data to an attacker-controlled S3 bucket, before installing AnyDesk for remote access.
ReportedView cited source - [5]
The attacker used AnyDesk to force the compromised host to boot into Safe Mode with Networking and disable both the Huntress agent and Microsoft Defender's real-time protection.
ReportedView cited source - [6]
Safe Mode is a Windows startup state designed for troubleshooting and diagnostics that starts Windows with a limited set of drivers and services, generally preventing most third-party software and services from loading.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comBill ToulasAug 13Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt
Additional citations
- BleepingComputer, reporting Huntress research
- Huntress



