RansomwareThe Register·1 week ago
Akira ransomware scum blocked victim's security tools – and broke their own encryptor
Gives a whole new meaning to Safe Mode
Every article that identifies Akira as responsible for or connected to reported activity.
Gives a whole new meaning to Safe Mode
An Akira ransomware affiliate attempted to evade endpoint detection and response tools by rebooting into Safe Mode to disable EDR and Windows Defender, but the technique backfired when the ransomware itself failed to execute in that environment. Huntress has documented the complete attack chain showing how this evasion tactic ultimately hindered the attacker's own encryption capabilities. The incident highlights the double-edged nature of Safe Mode abuse, where defensive measures can inadvertently impede malicious payloads.