Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Hits Safe Mode: Ransomware Rebooting Around EDR

0
Medium
Published: 08/12/2026 (08/12/2026, 16:42:10 UTC)
Source: AlienVault OTX General

Description

An Akira ransomware affiliate exploited an exposed SonicWall VPN lacking multi-factor authentication via credential spraying to gain initial access. After compromising the domain controller, the attacker performed Active Directory enumeration and exfiltrated data to cloud storage. The attacker used a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protections. AnyDesk was installed for persistent remote access. The ransomware failed to encrypt files due to out-of-memory errors in Safe Mode, but the attacker had already exfiltrated sensitive credentials and data, enabling extortion through data leak threats. This is the first known use of Safe Mode reboot as an anti-EDR technique by Akira affiliates.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 12:41:23 UTC

Technical Analysis

This incident involves an Akira ransomware affiliate gaining initial access through credential spraying against an exposed SonicWall VPN without multi-factor authentication. Following domain controller compromise, the attacker enumerated Active Directory and exfiltrated data using WinRAR and s5cmd to cloud storage. To evade endpoint detection and response (EDR) and antivirus tools, the attacker rebooted the victim system into Safe Mode with Networking, effectively disabling security software. AnyDesk was deployed as a persistent remote access tool. However, the ransomware payload failed to execute encryption due to out-of-virtual-memory errors in Safe Mode. Despite the encryption failure, the attacker successfully exfiltrated credentials and file shares, enabling double extortion via data leak threats. This represents the first observed use of Safe Mode reboot as an anti-EDR evasion technique by Akira ransomware affiliates.

Potential Impact

The attacker gained unauthorized access to the victim network, compromised the domain controller, and exfiltrated sensitive credentials and data. Although ransomware encryption failed due to Safe Mode limitations, the attacker retained the ability to extort the victim through threats of data leakage. The evasion technique of rebooting into Safe Mode disabled security protections, complicating detection and response efforts.

Defensive Guidance

No official patch or fix applies as this is an attack technique rather than a software vulnerability. Organizations should enforce multi-factor authentication on VPN access to prevent credential spraying attacks. Monitoring for unusual reboots into Safe Mode and unauthorized installation of remote access tools like AnyDesk can aid detection. Strengthening credential hygiene and limiting exposure of VPN services are recommended. Since this is a novel evasion technique, defenders should update detection and response strategies accordingly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.huntress.com/blog/akira-hits-safe-mode-ransomware-rebooting-around-edr"]
Adversary
Storm-1567
Pulse Id
6a7ca262c4921e41ead16a57
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hashe2356c742c74cce5c6b6100162d0071a3f71e2fed2ed895c2011061a95b3299a
hash61a1ad1b6a028a1833c85e6544383999
hashbb6f97878c8cbf762d69717b3480658fe9157ff0
hash414b9985f46714f44dd1bd63860d2a48dcfababcfe5c712a4b4f575378127a56

Ip

ValueDescriptionCopy
ip72.23.77.35

Threat ID: 6a7d9842bf8831d53906bd63

Added to database: 08/13/2026, 10:11:14 UTC

Last enriched: 08/13/2026, 12:41:23 UTC

Last updated: 08/13/2026, 16:36:36 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses