{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/akira/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["Akira"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SonicWall SSL VPN","Windows"],"_cs_severities":["high"],"_cs_tags":["ransomware","akira","edr-evasion","sonicwall"],"_cs_type":"threat","_cs_vendors":["SonicWall","Microsoft"],"content_html":"\u003cp\u003eIn early August 2026, a Huntress-observed Akira ransomware affiliate executed a targeted attack against a victim environment. The threat actor initially gained access through an exposed SonicWall SSL VPN appliance lacking multi-factor authentication. Following successful authentication, the attacker pivoted to the domain controller, conducted extensive Active Directory reconnaissance, and staged data for exfiltration. In a notable attempt to bypass endpoint detection and response (EDR) solutions and Microsoft Defender, the attacker modified the host boot configuration to force a reboot into Safe Mode with Networking. This maneuver successfully disabled third-party security agents; however, it also deprived the Akira ransomware payload of the necessary resources, resulting in an out-of-memory failure that prevented file encryption. Despite the failure of the ransomware detonation, the attacker successfully exfiltrated sensitive data to an external S3 bucket prior to the reboot.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access is established by the threat actor using valid credentials via an exposed SonicWall SSL VPN appliance (T1190).\u003c/li\u003e\n\u003cli\u003eThe attacker establishes remote persistent access using AnyDesk, identified by peer Client-ID 1778787240.\u003c/li\u003e\n\u003cli\u003eReconnaissance is performed on Active Directory, with output files written to C:\\ProgramData\\AdUsers.txt and C:\\ProgramData\\AdComp.txt (T1087.002).\u003c/li\u003e\n\u003cli\u003eData shares are discovered, collected, and compressed using WinRAR.exe (T1560.001).\u003c/li\u003e\n\u003cli\u003eStaged data is exfiltrated to an attacker-controlled S3 bucket using the s5cmd utility (T1567.002).\u003c/li\u003e\n\u003cli\u003eThe attacker executes a command to modify boot configuration via msconfig.exe, setting the system to reboot into Safe Mode (T1562.001).\u003c/li\u003e\n\u003cli\u003eThe system reboots into Safe Mode (EID 27: SAFEBOOT:NETWORK), which terminates EDR processes and disables Microsoft Defender real-time protection (T1547.001).\u003c/li\u003e\n\u003cli\u003eThe Akira payload attempts to execute in the restricted environment, causing an out-of-virtual-memory crash, thereby failing to encrypt the host.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eWhile the Akira ransomware encryption failed due to the host's transition into Safe Mode, the attacker successfully achieved data exfiltration. The loss of sensitive information exposes the organization to double-extortion tactics, where the actor threatens to publicly leak exfiltrated data unless a ransom is paid. The incident highlights a shifting landscape where ransomware affiliates are increasingly using environmental modification to evade automated security responses.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnable Sysmon or Windows Event Log auditing (Event ID 4697 or 7045) to detect modifications to the boot configuration via msconfig or BCDedit.\u003c/li\u003e\n\u003cli\u003eImplement a policy to restrict VPN access to specific source IP addresses and enforce mandatory MFA for all VPN and remote access sessions.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to alert on unauthorized attempts to set the Windows boot mode to 'Safe Mode'.\u003c/li\u003e\n\u003cli\u003eMonitor for the execution of file archival utilities like WinRAR.exe in non-standard directories or by non-admin accounts.\u003c/li\u003e\n\u003cli\u003eReview network egress logs for unauthorized data movement to cloud storage providers (specifically S3) using utilities like s5cmd.exe.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-18T20:50:45Z","date_published":"2026-08-18T20:50:45Z","id":"https://feed.craftedsignal.io/briefs/2026-08-akira-safe-mode/","summary":"An Akira ransomware affiliate gained initial access via a SonicWall VPN and attempted to evade security controls by rebooting the host into Safe Mode, an anti-EDR tactic that ultimately caused the ransomware to crash.","title":"Akira Ransomware Affiliate Abuses Safe Mode to Evade EDR","url":"https://feed.craftedsignal.io/briefs/2026-08-akira-safe-mode/"}],"language":"en","title":"CraftedSignal Threat Feed - Akira","version":"https://jsonfeed.org/version/1.1"}