← Threat Actors & APT Groups

Akira

Every article that identifies Akira as responsible for or connected to reported activity.

RansomwareHuntress Blog·1 week ago

Akira Hits Safe Mode: Ransomware Rebooting Around EDR

An Akira ransomware affiliate attempted to evade endpoint detection and response tools by rebooting into Safe Mode to disable EDR and Windows Defender, but the technique backfired when the ransomware itself failed to execute in that environment. Huntress has documented the complete attack chain showing how this evasion tactic ultimately hindered the attacker's own encryption capabilities. The incident highlights the double-edged nature of Safe Mode abuse, where defensive measures can inadvertently impede malicious payloads.