bleeping-computer · Crawled Aug 13, 2026

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

1 IoCs 1 Actors
Read original article ↗

AI Summary

An Akira ransomware affiliate gained initial access via an exposed SonicWall VPN without MFA, then used RDP to move laterally and exfiltrate data. The attacker rebooted the compromised host into Safe Mode with Networking to disable EDR and AV solutions, including the Huntress agent and Microsoft Defender. Data was stolen using s5cmd and uploaded to an attacker-controlled S3 bucket, while AnyDesk was installed and configured to persist in Safe Mode. The ransomware payload (akira.exe) failed to execute due to low virtual memory, preventing encryption. Despite the failure, the actor exfiltrated sensitive data within five hours.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 1 extracted

Type Value Detail
Filename akira.exe Details →

MITRE ATT&CK TTPs 27 techniques