Akira Ransomware Bypasses EDR via Safe Mode but Fails to Encrypt Files
The Akira ransomware group breached a corporate network on August 4, 2026, by exploiting a SonicWall SSL VPN that lacked multi-factor authentication, succeeding after numerous failed login attempts. Once inside, attackers enumerated Active Directory, compressed files from network shares using WinRAR, and exfiltrated the data to an attacker-controlled Amazon S3 bucket via s5cmd. They installed AnyDesk for persistent remote access and then rebooted the compromised systems into Safe Mode with Networking to disable endpoint detection and response tools, including Microsoft Defender. Although the Akira ransomware executable was launched in Safe Mode, the encryption process failed after 13 seconds due to a low virtual memory error. Data theft was confirmed as fully completed before the encryption attempt, meaning the breach resulted in exfiltration even without a successful ransomware deployment.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in