RansomwareAug 13, 2026
Akira Ransomware Affiliate Rebooted Into Safe Mode to Dodge EDR and Broke Its Own Attack
Akira ransomware affiliate rebooted server into Safe Mode to evade EDR, but it broke the ransomware.
Summary
An affiliate of the Akira ransomware operation attempted to bypass endpoint detection and response (EDR) by rebooting a compromised server into Windows Safe Mode. This maneuver successfully disabled both the EDR agent and Microsoft Defender. However, the stripped-down Safe Mode environment also caused the ransomware payload to crash, thwarting the attack.
Entities
Windows Safe Mode (product)Microsoft Defender (product)