Akira Ransomware Exploits Windows Safe Mode to Bypass Security in Latest Attack
Akira ransomware operators have adopted a new tactic to evade detection, leveraging Windows Safe Mode with Networking to disable endpoint protections before deploying encryption. In a recent intrusion analyzed by Huntress, attackers gained initial access through a credential-spraying attack on an exposed SonicWall SSL VPN lacking multi-factor authentication (MFA).
On August 4, the threat actor used stolen credentials to log into the VPN, then pivoted via Remote Desktop Protocol (RDP) to a domain controller. From there, they exported Active Directory data including user accounts, group memberships, and system details to map the network. Files were archived with WinRAR and exfiltrated to an attacker-controlled cloud storage bucket using the tool s5cmd.
To bypass security, the intruder installed AnyDesk as a persistent remote-access service and modified the Safe Mode registry to ensure it remained active after a reboot. At 06:29 UTC, they forced the system into Safe Mode with Networking, disabling Microsoft Defender’s real-time protection and the Huntress EDR agent. This created a blind spot while maintaining remote control.
The encryption attempt at 06:34 UTC failed due to insufficient virtual memory in Safe Mode, triggering errors that prevented the payload from executing. Defender later flagged the file as Ransom:Win32/Akira.B!ibt, but quarantine was blocked until the system rebooted into normal mode at 08:10 UTC.
Despite the failed encryption, the attack highlights broader risks: stolen credentials and exfiltrated data could still be used for extortion. Akira, one of the most active ransomware groups in 2025, has expanded its playbook with this Safe Mode technique, which while not new demands heightened monitoring for unexpected boot-configuration changes and security service disruptions.
The incident underscores vulnerabilities in exposed remote-access infrastructure, particularly VPNs without MFA. Indicators of compromise (IoCs) include the IP 72.23.77[.]35, the hostname WIN-DNCVG09TAT8, and specific file paths and commands used for enumeration and exfiltration. Security teams are advised to correlate VPN login spikes with subsequent Safe Mode events to detect similar intrusions early.
Source: https://cybersecuritynews.com/akira-uses-windows-safe-mode/
Huntress cybersecurity rating report: https://www.rankiteo.com/company/huntress-labs
SonicWall cybersecurity rating report: https://www.rankiteo.com/company/sonicwall
"id": "HUNSON1786611692",
"linkid": "huntress-labs, sonicwall",
"type": "Vulnerability",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'type': 'Organization'}],
'attack_vector': 'Credential Spraying, Remote Desktop Protocol (RDP)',
'data_breach': {'data_exfiltration': True,
'file_types_exposed': ['WinRAR Archives'],
'personally_identifiable_information': True,
'sensitivity_of_data': 'High (Personally Identifiable '
'Information, Network Infrastructure '
'Details)',
'type_of_data_compromised': ['Active Directory Data',
'User Accounts',
'Group Memberships',
'System Details']},
'date_detected': '2025-08-04T06:29:00Z',
'date_resolved': '2025-08-04T08:10:00Z',
'description': 'Akira ransomware operators leveraged Windows Safe Mode with '
'Networking to disable endpoint protections before deploying '
'encryption. The attack involved credential-spraying on an '
'exposed SonicWall SSL VPN without MFA, followed by RDP '
'pivoting, data exfiltration, and an attempted encryption in '
'Safe Mode that ultimately failed due to insufficient virtual '
'memory.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'data exfiltration and ransomware '
'attack',
'data_compromised': True,
'identity_theft_risk': 'High (Exfiltrated Active Directory data '
'including user accounts)',
'operational_impact': 'Potential disruption due to Safe Mode '
'reboot and security bypass attempts',
'systems_affected': ['Domain Controller',
'VPN',
'Endpoint Devices']},
'initial_access_broker': {'backdoors_established': ['AnyDesk as persistent '
'remote-access service'],
'entry_point': 'Exposed SonicWall SSL VPN',
'high_value_targets': ['Domain Controller']},
'investigation_status': 'Completed',
'lessons_learned': 'Exposed remote-access infrastructure, particularly VPNs '
'without MFA, poses significant risks. Safe Mode '
'techniques can bypass security controls, necessitating '
'heightened monitoring for unexpected boot-configuration '
'changes and security service disruptions.',
'motivation': 'Financial Gain (Ransomware Extortion)',
'post_incident_analysis': {'corrective_actions': ['Implement MFA on all '
'remote-access services',
'Enhance monitoring for '
'Safe Mode events and '
'security service '
'disruptions',
'Restrict RDP access and '
'improve network '
'segmentation'],
'root_causes': ['Exposed SonicWall SSL VPN without '
'MFA',
'Stolen credentials used in '
'credential-spraying attack',
'Lack of monitoring for Safe Mode '
'reboots and security service '
'disruptions']},
'ransomware': {'data_exfiltration': True, 'ransomware_strain': 'Akira'},
'recommendations': ['Enforce Multi-Factor Authentication (MFA) on all '
'remote-access services, including VPNs',
'Monitor for unexpected Safe Mode reboots and security '
'service disruptions',
'Correlate VPN login spikes with subsequent Safe Mode '
'events to detect intrusions early',
'Restrict RDP access and implement network segmentation '
'to limit lateral movement',
'Enhance endpoint detection and response (EDR) '
'capabilities to detect and block ransomware activity'],
'references': [{'source': 'Huntress'}],
'response': {'containment_measures': ['System reboot into normal mode to '
'restore security services'],
'enhanced_monitoring': ['Monitoring for unexpected '
'boot-configuration changes and security '
'service disruptions'],
'remediation_measures': ['Correlation of VPN login spikes with '
'Safe Mode events for early detection'],
'third_party_assistance': 'Huntress (Incident Analysis)'},
'threat_actor': 'Akira Ransomware Group',
'title': 'Akira Ransomware Exploits Windows Safe Mode to Bypass Security',
'type': 'Ransomware',
'vulnerability_exploited': 'Exposed SonicWall SSL VPN without Multi-Factor '
'Authentication (MFA)'}