An Akira ransomware affiliate broke into a victim network through a SonicWall SSL VPN account that was not protected by multi-factor authentication, stole credentials and files, and then tried to encrypt systems after rebooting a host into Safe Mode. Huntress says the attacker used credential spraying, Remote Desktop Protocol access to a domain controller, Active Directory enumeration, WinRAR and s5cmd for data theft, and AnyDesk for persistence and command-and-control, but the Safe Mode reboot appears to have broken the akira.exe encryptor on that host.
Why it matters: This matters because it shows a real Akira intrusion chain that defenders can act on now: protect VPN access with MFA, review SonicWall and remote-access logs, and hunt for RDP, AnyDesk, WinRAR, and s5cmd activity. Even though encryption failed on one system, the attackers still stole data, so affected organizations face extortion and potential downstream fraud or exposure.
Bill Toulas
2026.08.13
98% relevant
This article appears to describe the same underlying intrusion and adds concrete technical detail on how the Akira affiliate used an exposed SonicWall VPN without MFA, moved via RDP, exfiltrated data with WinRAR and s5cmd to S3, used AnyDesk, booted Windows into Safe Mode with Networking to disable Huntress and Microsoft Defender protections, and then failed to encrypt because the Akira payload hit memory errors.
2026.08.12
100% relevant
This article establishes a distinct incident-focused story about Akira tradecraft in a real intrusion, centered on VPN access without MFA, data theft, and a failed Safe Mode encryption attempt rather than a previously tracked vulnerability or broader campaign already listed.
← Back to all stories