RansomwareAug 13, 2026
Akira Ransomware Affiliate Rebooted Into Safe Mode to Dodge EDR and Broke Its Own Attack
Akira ransomware affiliate rebooted server into Safe Mode to evade EDR, but it broke the ransomware.
Vendor Watch
Run Windows Safe Mode?
Get an email when a reviewed story names Windows Safe Mode, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
An affiliate of the Akira ransomware operation attempted to bypass endpoint detection and response (EDR) by rebooting a compromised server into Windows Safe Mode. This maneuver successfully disabled both the EDR agent and Microsoft Defender. However, the stripped-down Safe Mode environment also caused the ransomware payload to crash, thwarting the attack.
Entities
Windows Safe Mode (product)Microsoft Defender (product)