Back to Feed
RansomwareAug 13, 2026

Akira Ransomware Affiliate Rebooted Into Safe Mode to Dodge EDR and Broke Its Own Attack

Akira ransomware affiliate rebooted server into Safe Mode to evade EDR, but it broke the ransomware.

Vendor Watch

Run Windows Safe Mode?

Get an email when a reviewed story names Windows Safe Mode, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works

Summary

An affiliate of the Akira ransomware operation attempted to bypass endpoint detection and response (EDR) by rebooting a compromised server into Windows Safe Mode. This maneuver successfully disabled both the EDR agent and Microsoft Defender. However, the stripped-down Safe Mode environment also caused the ransomware payload to crash, thwarting the attack.

Entities

Windows Safe Mode (product)Microsoft Defender (product)