"the host had no working EDR, and AV was blinded," Huntress says.
Initial access: an exposed SonicWall VPN without MFA on August 4
Huntress reports the incident began on August 4 after an attacker gained entry through an exposed SonicWall VPN device that did not require multi-factor authentication (MFA). Roughly two hours after a successful VPN login, the attacker connected to the environment’s domain controller via RDP, enumerated Active Directory users and computers, and then moved laterally to an application server.
Data collection and exfiltration: WinRAR, s5cmd and an attacker-controlled S3 bucket
On the application server the attacker archived mapped file shares using WinRAR and then used the s5cmd command-line tool to upload the stolen archives to an attacker-controlled S3 bucket. The intruder also installed AnyDesk for persistent remote access before attempting further disruptive actions.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadSafe Mode with Networking: how EDR and real‑time AV were temporarily disabled
Using AnyDesk the attacker forced the compromised host to boot into Safe Mode with Networking. Safe Mode starts Windows with a limited set of drivers and services, and in this case prevented third-party security tooling from loading. Huntress says that for 10 minutes while in Safe Mode the host had no working endpoint detection and response (EDR) and Microsoft Defender’s real-time protection was effectively blinded. The attacker also added AnyDesk to Windows’ Safe Mode registry so the remote-access tool would start after reboot and retain access to the machine.
Ransomware failed to execute; Defender later quarantined the payload
While in Safe Mode the intruder attempted to run the main ransomware payload (akira.exe) via AnyDesk, but the executable failed to launch. The system reported low virtual memory and generated out‑of‑memory and PowerShell errors. A scheduled Microsoft Defender scan eventually detected the Akira executable even though real‑time protection had been disabled in Safe Mode, but Defender could not remove the file while the machine remained in that boot state. Only after the attacker rebooted the system into normal mode — which restored real‑time protection — did Defender quarantine the file. Despite the failure to encrypt files, Huntress says the Akira operator stole credentials and files for data extortion, completing theft and access activities in less than five hours from initial access.
Observed trend: Safe Mode abuse has precedents and implications for detection
Huntress notes other ransomware families including Snatch and AvosLocker have used the Safe Mode approach for years; this incident marks the first time the company has observed the tactic in an Akira attack. The researchers recommend several specific defensive steps: add MFA to all VPN accounts, deploy credential‑spraying detection measures, and monitor for Safe Mode boot configuration changes or remote‑access tools being added to the Safe Mode service registry.
How technologists, procurement leaders, and affected enterprises should respond
- Technologists and security teams: prioritize MFA for VPN accounts and add telemetry to detect Safe Mode boots and registry additions that enable remote tools to run in Safe Mode, as the attack chain moved from valid credentials to persistent remote access in a matter of hours.
- Procurement and infrastructure leaders: review remote-access and VPN configurations for exposed devices without MFA and evaluate whether devices like the SonicWall VPN in this incident are protected by centrally enforced authentication and monitoring controls.
- Affected enterprises and IT operations: be prepared for exfiltration even when encryption fails — Huntress documented WinRAR archives uploaded via s5cmd to an S3 bucket and stolen credentials used for extortion, all completed in under five hours from initial access.
Huntress’s broader analysis underlines a sharper point from its Blue Report 2026: "Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply." The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments — and this incident shows how quickly credential-based access can shift an intrusion from preventable to deeply intrusive.
Read the original Huntress write-up at BleepingComputer: https://www.bleepingcomputer.com/news/security/akira-hackers-disable-edr-with-safe-mode-steal-data-but-fail-to-encrypt/




