SecBriefs
← All briefs

Akira ransomware rebooted a victim into Safe Mode to weaken EDR

The attack shows how criminals can change the operating environment rather than fight security tools directly.

Hand-drawn SecBriefs editorial illustration: Akira ransomware rebooted a victim into Safe Mode to weaken EDRSOURCE · Security Affairs
© 2026 SecBriefs · Original illustration

THE BRIEF

An Akira ransomware affiliate attempted to restart systems in Windows Safe Mode, where many endpoint controls do not operate normally, to reduce resistance before encryption. In the reported case, part of the attack failed—but the technique remains important.

WHY IT MATTERS

EDR is strongest when it is running and visible. Attackers increasingly manipulate boot modes, drivers and recovery tooling to remove that advantage before carrying out destructive actions.

WHO SHOULD CARE

Windows administrators, SOCs, incident responders and organizations exposed to ransomware.

WHAT TO DO NOW

  • Alert on unexpected Safe Mode configuration and reboot commands.
  • Protect recovery and boot settings from ordinary administrators.
  • Test whether critical telemetry survives degraded startup modes.

VERIFICATION NOTE

Source basis: Security Affairs reporting. The attacker’s failure in one incident should not be read as proof that the technique is harmless.

Read original at Security Affairs

SecBriefs adds context and practical guidance. Reporting remains credited and linked to the original publisher.