As cited
Citation snapshot as of .
ransomware
Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt
An Akira ransomware affiliate disabled endpoint detection and response (EDR) protection by booting a compromised system into Safe Mode with Networking, then exfiltrated data but did not complete encryption of the target environment.
Why it matters: Organizations using Akira as a threat model need to ensure EDR solutions remain active across all boot modes and implement detection for Safe Mode restarts; this incident demonstrates a bypass technique that defenders should monitor for.
- Source published
- First seen by Cybersecurity Tracker