Akira Used Safe Mode to Silence EDR

Huntress says an Akira affiliate used a familiar SonicWall-to-Active Directory ransomware chain in an early-August intrusion, then rebooted the Windows host into Safe Mode to turn off Huntress EDR and Microsoft Defender before detonation. The same incident also showed the group’s usual spray, VPN login, domain-controller access, and data staging. Safe Mode starts only core Microsoft drivers and services, so third-party security tools stay out while the machine still has network access. In this case, that gave the operator a window where endpoint controls were effectively absent; Huntress says the ransomware’s own encryptor may also have broken in that mode, leaving boot artifacts and other Windows traces defenders can watch for. The lasting point is the shift in where detection has to happen. If a fleet can be rebooted into Safe Mode, the warning surface moves from malware alerts on the host to boot and service behavior, and the same path can apply on managed Windows endpoints even without SonicWall in the mix.

Part of the PlainSec briefing for 2026-08-12

Editions

Sources