Akira Hits Safe Mode: Ransomware Rebooting Around EDR
AI summary · glm-5.3-flash
Huntress documents an Akira ransomware affiliate rebooting endpoints into Windows Safe Mode to evade EDR and Defender, though Safe Mode broke the ransomware.
Huntress observed an Akira ransomware affiliate rebooting victim machines into Windows Safe Mode to disable EDR and Microsoft Defender before deploying ransomware. In an ironic twist, Safe Mode also prevented the ransomware from executing properly. The post walks through the full attack chain and the defensive lessons.
- Akira affiliate rebooted hosts into Windows Safe Mode to bypass EDR and Defender
- Safe Mode ironically broke the ransomware's own execution
- Huntress documents the full attack chain
Full article
An Akira affiliate rebooted into Safe Mode to kill EDR and Defender, then Safe Mode broke their own ransomware. Here’s the full attack chain.
This source does not provide full text. Read it at huntress.com.