Breaking
AI Edge Daily Briefing — 5 August 2026AI Edge Daily Briefing — 25 July 2026AI Edge Daily Briefing — 13 August 2026AI Edge Daily Briefing — 22 July 2026AI Edge Daily Briefing — 28 July 2026AI Edge Daily Briefing — 4 August 2026AI Edge Daily Briefing — 23 July 2026AI Edge Daily Briefing — 8 August 2026AI Edge Daily Briefing — 22 July 2026AI Edge Daily Briefing — 3 August 2026AI Edge Daily Briefing — 11 August 2026AI Edge Daily Briefing — 31 July 2026AI Edge Daily Briefing — 6 August 2026AI Edge Daily Briefing — 9 August 2026AI Edge Daily Briefing — 10 August 2026AI Edge Daily Briefing — 24 July 2026AI Edge Daily Briefing — 29 July 2026AI Edge Daily Briefing — 27 July 2026AI Edge Daily Briefing — 7 August 2026AI Edge Daily Briefing — 30 July 2026AI Edge Daily Briefing — 5 August 2026AI Edge Daily Briefing — 25 July 2026AI Edge Daily Briefing — 13 August 2026AI Edge Daily Briefing — 22 July 2026AI Edge Daily Briefing — 28 July 2026AI Edge Daily Briefing — 4 August 2026AI Edge Daily Briefing — 23 July 2026AI Edge Daily Briefing — 8 August 2026AI Edge Daily Briefing — 22 July 2026AI Edge Daily Briefing — 3 August 2026AI Edge Daily Briefing — 11 August 2026AI Edge Daily Briefing — 31 July 2026AI Edge Daily Briefing — 6 August 2026AI Edge Daily Briefing — 9 August 2026AI Edge Daily Briefing — 10 August 2026AI Edge Daily Briefing — 24 July 2026AI Edge Daily Briefing — 29 July 2026AI Edge Daily Briefing — 27 July 2026AI Edge Daily Briefing — 7 August 2026AI Edge Daily Briefing — 30 July 2026
Economy

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. [...]

Source: BleepingComputer · August 14, 2026 at 4:08 AM · AI-assisted report

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt
Photo: Coolcaesar / CC BY-SA 4.0

KUALA LUMPUR, 14 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

Hackers Exploit Safe Mode to Bypass Security in Akira Ransomware Attack

Market Impact

KUALA LUMPUR, Aug 13 — Cybercriminals affiliated with the Akira ransomware gang disabled endpoint detection and response (EDR) tools by rebooting a compromised system into Safe Mode with Networking, stealing data without encrypting files, according to cybersecurity firm Huntress.

The attack, detected on Aug. 4, began after hackers gained initial access through an unsecured SonicWall VPN device lacking multi-factor authentication (MFA). Within two hours of a successful VPN login, the attackers connected to the domain controller via Remote Desktop Protocol (RDP), enumerated Active Directory users and computers, and moved laterally to an application server.

Using tools such as WinRAR and the command-line utility s5cmd, the threat actors archived mapped file shares and uploaded stolen data to an attacker-controlled Amazon S3 bucket. They then installed AnyDesk for persistent remote access. The attackers exploited AnyDesk to force the compromised host into Safe Mode with Networking, a Windows diagnostic mode that loads minimal drivers and services, effectively disabling the Huntress EDR agent and Microsoft Defender’s real-time protection.

For 10 minutes, the host operated without active EDR or antivirus (AV) monitoring, Huntress reported. The attackers also modified the Windows registry to ensure AnyDesk would launch automatically in Safe Mode, maintaining remote access even after reboots. However, their attempt to execute the Akira ransomware payload (akira.exe) failed due to low virtual memory, triggering out-of-memory and PowerShell errors.

A scheduled Microsoft Defender scan later detected the Akira executable, though real-time protection had been disabled in Safe Mode. Defender quarantined the file only after the system was rebooted into normal mode, restoring full AV functionality.

Despite failing to encrypt files, the Akira operators successfully exfiltrated credentials and sensitive data within five hours of initial access. Huntress noted this marks the first observed instance of such a tactic in an Akira attack, though other ransomware families like Snatch and AvosLocker have used similar methods for years.

The incident underscores the risks of relying solely on prevention-based security models. Once attackers gain valid credentials, traditional prevention measures become less effective. Huntress recommends enforcing MFA on all VPN accounts, deploying credential-spraying detection, and monitoring for unauthorized Safe Mode boot configurations or additions to the Safe Mode service registry.

The findings are part of Huntress’ broader analysis of ransomware tactics, as detailed in its The Blue Report 2026, which evaluates defense effectiveness across 338 million simulated cyberattacks in production environments.

Malaysia’s cybersecurity landscape remains vulnerable to such sophisticated attacks, particularly among organizations with exposed remote access points or weak authentication controls. The use of legitimate remote management tools like AnyDesk highlights the need for continuous monitoring and behavioral detection to identify anomalous system modifications.

Industry experts stress that while prevention scores may appear strong, post-compromise detection and response capabilities are critical in mitigating dwell time and data theft. The Akira incident serves as a reminder for Malaysian enterprises to audit VPN configurations, enforce MFA, and review Active Directory hygiene to reduce exposure to ransomware affiliates leveraging evasion techniques.

Related: Microsoft

Reporting based on BleepingComputer. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.