Hits Safe Mode: Ransomware Rebooting Around EDR
An Akira ransomware affiliate exploited an exposed SonicWall VPN lacking multi-factor authentication via credential spraying to gain initial access. After compromising the domain controller, the attacker performed Active Directory enumeration and exfiltrated data to cloud storage. The attacker used a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protections. AnyDesk was installed for persistent remote access. The ransomware failed to encrypt files due to out-of-memory errors in Safe Mode, but the attacker had already exfiltrated sensitive credentials and data, enabling extortion through data leak threats. This is the first known use of Safe Mode reboot as an anti-EDR technique by Akira affiliates.
AI Analysis
Technical Summary
This incident involves an Akira ransomware affiliate gaining initial access through credential spraying against an exposed SonicWall VPN without multi-factor authentication. Following domain controller compromise, the attacker enumerated Active Directory and exfiltrated data using WinRAR and s5cmd to cloud storage. To evade endpoint detection and response (EDR) and antivirus tools, the attacker rebooted the victim system into Safe Mode with Networking, effectively disabling security software. AnyDesk was deployed as a persistent remote access tool. However, the ransomware payload failed to execute encryption due to out-of-virtual-memory errors in Safe Mode. Despite the encryption failure, the attacker successfully exfiltrated credentials and file shares, enabling double extortion via data leak threats. This represents the first observed use of Safe Mode reboot as an anti-EDR evasion technique by Akira ransomware affiliates.
Potential Impact
The attacker gained unauthorized access to the victim network, compromised the domain controller, and exfiltrated sensitive credentials and data. Although ransomware encryption failed due to Safe Mode limitations, the attacker retained the ability to extort the victim through threats of data leakage. The evasion technique of rebooting into Safe Mode disabled security protections, complicating detection and response efforts.
Mitigation Recommendations
No official patch or fix applies as this is an attack technique rather than a software vulnerability. Organizations should enforce multi-factor authentication on VPN access to prevent credential spraying attacks. Monitoring for unusual reboots into Safe Mode and unauthorized installation of remote access tools like AnyDesk can aid detection. Strengthening credential hygiene and limiting exposure of VPN services are recommended. Since this is a novel evasion technique, defenders should update detection and response strategies accordingly.
Indicators of Compromise
- hash: e2356c742c74cce5c6b6100162d0071a3f71e2fed2ed895c2011061a95b3299a
- hash: 61a1ad1b6a028a1833c85e6544383999
- hash: bb6f97878c8cbf762d69717b3480658fe9157ff0
- hash: 414b9985f46714f44dd1bd63860d2a48dcfababcfe5c712a4b4f575378127a56
- ip: 72.23.77.35
Hits Safe Mode: Ransomware Rebooting Around EDR
Description
An Akira ransomware affiliate exploited an exposed SonicWall VPN lacking multi-factor authentication via credential spraying to gain initial access. After compromising the domain controller, the attacker performed Active Directory enumeration and exfiltrated data to cloud storage. The attacker used a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protections. AnyDesk was installed for persistent remote access. The ransomware failed to encrypt files due to out-of-memory errors in Safe Mode, but the attacker had already exfiltrated sensitive credentials and data, enabling extortion through data leak threats. This is the first known use of Safe Mode reboot as an anti-EDR technique by Akira affiliates.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This incident involves an Akira ransomware affiliate gaining initial access through credential spraying against an exposed SonicWall VPN without multi-factor authentication. Following domain controller compromise, the attacker enumerated Active Directory and exfiltrated data using WinRAR and s5cmd to cloud storage. To evade endpoint detection and response (EDR) and antivirus tools, the attacker rebooted the victim system into Safe Mode with Networking, effectively disabling security software. AnyDesk was deployed as a persistent remote access tool. However, the ransomware payload failed to execute encryption due to out-of-virtual-memory errors in Safe Mode. Despite the encryption failure, the attacker successfully exfiltrated credentials and file shares, enabling double extortion via data leak threats. This represents the first observed use of Safe Mode reboot as an anti-EDR evasion technique by Akira ransomware affiliates.
Potential Impact
The attacker gained unauthorized access to the victim network, compromised the domain controller, and exfiltrated sensitive credentials and data. Although ransomware encryption failed due to Safe Mode limitations, the attacker retained the ability to extort the victim through threats of data leakage. The evasion technique of rebooting into Safe Mode disabled security protections, complicating detection and response efforts.
Defensive Guidance
No official patch or fix applies as this is an attack technique rather than a software vulnerability. Organizations should enforce multi-factor authentication on VPN access to prevent credential spraying attacks. Monitoring for unusual reboots into Safe Mode and unauthorized installation of remote access tools like AnyDesk can aid detection. Strengthening credential hygiene and limiting exposure of VPN services are recommended. Since this is a novel evasion technique, defenders should update detection and response strategies accordingly.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.huntress.com/blog/akira-hits-safe-mode-ransomware-rebooting-around-edr"]
- Adversary
- Storm-1567
- Pulse Id
- 6a7ca262c4921e41ead16a57
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hashe2356c742c74cce5c6b6100162d0071a3f71e2fed2ed895c2011061a95b3299a | — | |
hash61a1ad1b6a028a1833c85e6544383999 | — | |
hashbb6f97878c8cbf762d69717b3480658fe9157ff0 | — | |
hash414b9985f46714f44dd1bd63860d2a48dcfababcfe5c712a4b4f575378127a56 | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip72.23.77.35 | — |
Threat ID: 6a7d9842bf8831d53906bd63
Added to database: 08/13/2026, 10:11:14 UTC
Last enriched: 08/13/2026, 12:41:23 UTC
Last updated: 08/13/2026, 16:36:36 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.