Threats Tagged 'safe mode'
View all threats tagged with 'safe mode'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'safe mode'
Click on any threat for detailed analysis and mitigation recommendations
Hits Safe Mode: Ransomware Rebooting Around EDR 0 An Akira ransomware affiliate exploited an exposed SonicWall VPN lacking multi-factor authentication via credential spraying to gain initial access. After compromising the domain controller, the attacker performed Active Directory enumeration and exfiltrated data to cloud storage. The attacker used a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protections. AnyDesk was installed for persistent remote access. The ransomware failed to encrypt files due to out-of-memory errors in Safe Mode, but the attacker had already exfiltrated sensitive credentials and data, enabling extortion through data leak threats. This is the first known use of Safe Mode reboot as an anti-EDR technique by Akira affiliates. Join the discussion | AlienVault OTX General | 08/12/2026, 16:42:10 UTC Added: 08/13/2026, 10:11:14 UTC |
Showing 1 to 1 of 1 result