# Akira ransomware Safe Mode evasion tactic

> Live situation record from CLSTR: https://clstr.news/situations/akira-ransomware-safe-mode-evasion-tactic
> Updated: 2026-08-16T03:25:03.000Z. Sources: 7. Developments: 2.

Akira ransomware affiliates have developed a tactic to bypass security tools by forcing compromised Windows systems to reboot into Safe Mode with Networking. This method aims to neutralize endpoint detection and response (EDR) solutions, such as Microsoft Defender and Huntress, which often fail to load essential drivers or services in a minimal startup environment.

The attack chain typically begins with credential-spraying campaigns against VPN devices, such as SonicWall, that lack multi-factor authentication (MFA). Once initial access is gained, attackers move laterally via Remote Desktop Protocol (RDP), archive file shares, and exfiltrate data to attacker-controlled Amazon S3 buckets using tools like s5cmd. Attackers may also install remote access software like AnyDesk and modify registry keys to maintain persistence.

While this technique successfully blinds security telemetry, the final encryption phase has demonstrated instability. In observed incidents, the ransomware payload failed to execute within the Safe Mode environment due to system errors related to PowerShell failures and low virtual memory.

## Timeline

### 2026-08-16: Akira ransomware uses Safe Mode to bypass security tools

Akira ransomware attackers are bypassing EDR and Microsoft Defender by forcing Windows systems into Safe Mode to facilitate data exfiltration, though the encryption payload has faced stability issues.

3 sources. https://clstr.news/cluster/akira-ransomware-uses-safe-mode-to-bypass-security-tools

### 2026-08-12: Akira ransomware uses Windows Safe Mode to bypass security tools

Akira ransomware attackers are using Windows Safe Mode to disable security tools. While one recent attempt failed to encrypt files, attackers successfully stole data after exploiting a VPN lacking MFA.

4 sources. https://clstr.news/cluster/akira-ransomware-uses-windows-safe-mode-to-bypass-security-tools

---
Cite as: Akira ransomware Safe Mode evasion tactic. CLSTR, https://clstr.news/situations/akira-ransomware-safe-mode-evasion-tactic
