Threats · 45 days ago
Huntress says an Akira affiliate used a familiar SonicWall-to-Active Directory ransomware chain in an early-August intrusion, then rebooted the Windows host into Safe Mode to turn off Huntress EDR and Microsoft Defender before detonation. The same incident also showed the group’s usual spray, VPN login, domain-controller access, and data staging.
Safe Mode starts only core Microsoft drivers and services, so third-party security tools stay out while the machine still has network access. In this case, that gave the operator a window where endpoint controls were effectively absent; Huntress says the ransomware’s own encryptor may also have broken in that mode, leaving boot artifacts and other Windows traces defenders can watch for.
The lasting point is the shift in where detection has to happen. If a fleet can be rebooted into Safe Mode, the warning surface moves from malware alerts on the host to boot and service behavior, and the same path can apply on managed Windows endpoints even without SonicWall in the mix.
4 sources covering this story
Akira ransomware reboots into Windows Safe Mode to knock EDR offline
The tactic disabled endpoint defenses as intended, but also accidentally broke the ransomware’s encryption process.
Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt
An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking.
Akira Affiliate Crashes Ransomware After Attempting EDR Evasion
Huntress documents how a ransomware affiliate sabotaged its own attack with an anti-EDR effort
Akira Hits Safe Mode: Ransomware Rebooting Around EDR | Huntress
An Akira affiliate rebooted into Safe Mode to kill EDR and Defender, then Safe Mode broke their own ransomware.
Part of the PlainSec briefing for 2026-08-13