Akira ransomware rebooted a victim into Safe Mode to weaken EDR
The attack shows how criminals can change the operating environment rather than fight security tools directly.
SOURCE · Security AffairsTHE BRIEF
An Akira ransomware affiliate attempted to restart systems in Windows Safe Mode, where many endpoint controls do not operate normally, to reduce resistance before encryption. In the reported case, part of the attack failed—but the technique remains important.
WHY IT MATTERS
EDR is strongest when it is running and visible. Attackers increasingly manipulate boot modes, drivers and recovery tooling to remove that advantage before carrying out destructive actions.
WHO SHOULD CARE
Windows administrators, SOCs, incident responders and organizations exposed to ransomware.
WHAT TO DO NOW
- Alert on unexpected Safe Mode configuration and reboot commands.
- Protect recovery and boot settings from ordinary administrators.
- Test whether critical telemetry survives degraded startup modes.
VERIFICATION NOTE
Source basis: Security Affairs reporting. The attacker’s failure in one incident should not be read as proof that the technique is harmless.
SecBriefs adds context and practical guidance. Reporting remains credited and linked to the original publisher.