Back to Feed
RansomwareAug 13, 2026

Akira Ransomware Affiliate Rebooted Into Safe Mode to Dodge EDR and Broke Its Own Attack

Akira ransomware affiliate rebooted server into Safe Mode to evade EDR, but it broke the ransomware.

Summary

An affiliate of the Akira ransomware operation attempted to bypass endpoint detection and response (EDR) by rebooting a compromised server into Windows Safe Mode. This maneuver successfully disabled both the EDR agent and Microsoft Defender. However, the stripped-down Safe Mode environment also caused the ransomware payload to crash, thwarting the attack.

Entities

Windows Safe Mode (product)Microsoft Defender (product)