Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Dark bordered beauty moth found in Northumberland after 70 years

    August 14, 2026

    Nigel Farage wins Clacton byelection in contest boycotted by every other major party | Nigel Farage

    August 14, 2026

    Burnham won’t fix our prisons crisis until he dares to be honest with the public about crime | Polly Toynbee

    August 14, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Dark bordered beauty moth found in Northumberland after 70 years
    • Nigel Farage wins Clacton byelection in contest boycotted by every other major party | Nigel Farage
    • Burnham won’t fix our prisons crisis until he dares to be honest with the public about crime | Polly Toynbee
    • Hot topic: why is Burnham so reluctant to talk about the climate crisis? | Andy Burnham
    • Acer Promo Codes: 40% Off
    • Create a Reasoning-Focused LLM: A Practical Guide to Streaming, Curating, and Fine-Tuning the SupraLabs Reasoning Corpus
    • Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
    • Morgan Stanley’s Bitcoin ETF drew $371 million of share contributions while Bitcoin erased $66.8 million
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, August 14
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 14, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking.

    The attack occurred on August 4 after the hacker obtained initial access through an exposed SonicWall VPN device without multi-factor authentication (MFA).

    Managed detection and response (MDR) services company Huntress says that roughly two hours after a successful VPN login, the attacker connected to the domain controller via RDP, enumerated Active Directory users and computers, and then moved to an application server.

    image

    They used WinRAR to archive mapped file shares and the s5cmd command-line tool to upload the stolen data to an attacker-controlled S3 bucket, before installing AnyDesk for remote access.

    At that stage, the attacker used AnyDesk to force the compromised host to boot into Safe Mode with Networking and disable both the Huntress agent and Microsoft Defender’s real-time protection.

    Safe Mode is a Windows startup state designed for troubleshooting and diagnostic operations. It starts Windows with a limited set of drivers and services, generally preventing most third-party software and services from loading.

    For 10 minutes while in Safe Mode, “the host had no working EDR, and AV was blinded,” Huntress says.

    Meanwhile, the attackers added AnyDesk to Windows’ Safe Mode registry, allowing it to start after reboot and retain their remote access to the breached machine.

    However, when they attempted to launch the main ransomware payload (akira.exe) via AnyDesk in Safe Mode, it failed to execute as the system reported low virtual memory and generated out-of-memory and PowerShell errors.

    Akira attack flow
    Akira ransomware attack flow
    Source: Huntress

    A scheduled Defender scan eventually detected the Akira executable, even if real-time protection was disabled in Safe Mode, but the security tool could not remove it while the machine remained in that mode.

    Defender quarantined the file only after the attacker rebooted the system into normal mode, which restored real-time protection.

    Despite the failure to encrypt files, the Akira operator still managed to steal credentials and files for data extortion, all in less than five hours from initial access.

    Huntress notes that other ransomware families, such as Snatch and AvosLocker, have used this tactic for years, but this incident marks the first time the company observed it in an Akira attack.

    The researchers recommend adding MFA to all VPN accounts, placing credential-spraying detection measures, and monitoring for Safe Mode boot configuration changes or remote-access tools being added to the Safe Mode service registry.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    Akira data disable EDR encrypt fail hackers mode Safe Steal
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

    Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks

    Soluna has 6.3 GW of data center projects on paper, only 192 MW are operating

    Belgium’s eID Authentication Opens Citizen Accounts to RCE

    Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

    This free Android assistant fixes my biggest Gemini frustration – and keeps my data private

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Dark bordered beauty moth found in Northumberland after 70 years

    August 14, 2026

    Nigel Farage wins Clacton byelection in contest boycotted by every other major party | Nigel Farage

    August 14, 2026

    Burnham won’t fix our prisons crisis until he dares to be honest with the public about crime | Polly Toynbee

    August 14, 2026

    Hot topic: why is Burnham so reluctant to talk about the climate crisis? | Andy Burnham

    August 14, 2026
    Latest Posts

    Evacuated villagers in Cairngorms allowed home after wildfire threat lifts | Wildfires

    July 25, 2026

    The Fraternal Order Of Police Supports The Clarity Act.

    July 25, 2026

    How Synthetic Identity Fraud is Coming for Machine Identities

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Dark bordered beauty moth found in Northumberland after 70 years

    August 14, 2026

    Nigel Farage wins Clacton byelection in contest boycotted by every other major party | Nigel Farage

    August 14, 2026

    Burnham won’t fix our prisons crisis until he dares to be honest with the public about crime | Polly Toynbee

    August 14, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.