← Back
RansomwareThe Register·1 week ago

Akira ransomware scum blocked victim's security tools – and broke their own encryptor

Gives a whole new meaning to Safe Mode

Read full article at The Register

Related Articles

RansomwareHuntress Blog·1 week ago

Akira Hits Safe Mode: Ransomware Rebooting Around EDR

An Akira ransomware affiliate attempted to evade endpoint detection and response tools by rebooting into Safe Mode to disable EDR and Windows Defender, but the technique backfired when the ransomware itself failed to execute in that environment. Huntress has documented the complete attack chain showing how this evasion tactic ultimately hindered the attacker's own encryption capabilities. The incident highlights the double-edged nature of Safe Mode abuse, where defensive measures can inadvertently impede malicious payloads.