The Akira ransomware attack has drawn attention for its use of Safe Mode to bypass security products, highlighting a sophisticated approach to defeating endpoint defences. In this incident, the attackers compromised a SonicWall SSL VPN lacking multi-factor authentication, eventually disabling security tools but inadvertently sabotaging their own encryption process. This case offers crucial insights into the evolving tactics of ransomware affiliates.
How the Akira Ransomware Attack Unfolded
The Akira ransomware group is known for its targeted attacks against organisations, using advanced methods to infiltrate networks and evade detection. The latest incident, investigated by Huntress in early August 2026, illustrates a typical but well-organised attack chain. The attackers initially targeted the organisation’s SonicWall SSL VPN, which did not have multi-factor authentication (MFA) enabled.
The timeline began on August 4, when the VPN registered a credential-spraying attack. This involved a burst of failed logins using invalid credentials, which the VPN successfully blocked. However, just seven minutes later, the attackers gained access using valid credentials for an account that was not protected by MFA. This small window of opportunity marked the start of a damaging intrusion.
Compromising the Domain Controller and Network Enumeration
With VPN access secured, the attackers moved rapidly through the environment. They used Remote Desktop Protocol (RDP) to access the domain controller, the central point of identity and access management in most corporate networks. Once inside, the attackers employed Active Directory queries to enumerate the entire domain, collecting details about users, groups, computers and other resources. According to Huntress, this enumeration included a “full-property dump of every user and every computer in the domain,” providing a comprehensive map for lateral movement and further exploitation.
Data Exfiltration and Persistence
The next phase involved data theft and establishing persistence. The attackers targeted an application server, downloading and using WinRAR to archive files from mapped network shares. This data was then exfiltrated to cloud storage using s5cmd, a high-speed S3 transfer utility. To maintain ongoing access, the attackers installed AnyDesk, a legitimate remote desktop tool, configured to start automatically with Windows. This allowed them to use AnyDesk as a remote access trojan and a command-and-control channel, enabling hands-on control and further malware deployment, including the akira.exe ransomware payload.
- Initial access via SonicWall SSL VPN with no MFA
- Lateral movement to domain controller using RDP
- Comprehensive Active Directory enumeration
- Data theft with WinRAR and s5cmd
- Persistence via AnyDesk installation
Safe Mode Reboot: Disabling Security Tools and Failing Encryption
Three hours into the attack, the Akira affiliate took a bold step by forcing a reboot of the victim’s system into Safe Mode with Networking. Safe Mode is designed to load only essential Windows drivers and services, which has the side effect of disabling most third-party security tools, including endpoint detection and response products. This tactic, long used by ransomware groups such as Snatch and AvosLocker, had not previously been observed in Akira incidents.
The intent was clear: by booting into Safe Mode, the attackers aimed to prevent both the Huntress agent and Microsoft Defender’s real-time protection from interfering with their ransomware deployment. This approach successfully disabled these defences, allowing the attackers to launch the akira.exe binary on the compromised endpoint.
However, the plan backfired. The limited function of Safe Mode also broke the ransomware’s own encryptor. According to James Northey of Huntress, this was likely a memory-configuration issue: the system did not provide enough virtual memory for akira.exe to complete its encryption routine. As a result, the ransomware failed to lock files, sparing the victim from the worst-case scenario of total data loss.
Despite this failure, the attackers had already exfiltrated valuable data and stolen credentials, meaning the breach still had serious consequences. Northey warned that this outcome should not be seen as a reliable defence, as future attacks could succeed with different system configurations or improved ransomware tooling.
Why This Akira Ransomware Attack Matters
This incident demonstrates how ransomware affiliates are adapting their tactics to defeat increasingly sophisticated endpoint protections. The use of Safe Mode to disable security tools is a growing trend, and attackers are likely to refine their approaches to ensure their malware functions even in restricted environments. The fact that data theft and credential compromise occurred before the failed encryption highlights the multifaceted impact of modern ransomware attacks.
What Organisations Should Do Now
- Enable multi-factor authentication on all remote access systems, especially VPNs.
- Monitor for and restrict abuse of legitimate remote access tools like AnyDesk.
- Review controls to prevent and detect Safe Mode abuse.
The Akira ransomware case underscores the necessity of strong authentication and monitoring across remote and privileged access pathways. Lessons from this attack can help organisations address current methods used by ransomware actors.
Originally reported by theregister.com.





