A recent incident involving Akira ransomware affiliates has revealed a notable tactic: disabling endpoint detection and response (EDR) solutions by rebooting compromised systems into Safe Mode with Networking. This approach allowed the attackers to evade detection and steal sensitive data. Notably, the attackers failed to encrypt the stolen data, suggesting a potential misstep in their operational planning. The use of Safe Mode to disable EDR solutions highlights the ongoing cat-and-mouse game between attackers and defenders, with each side continually adapting and evolving their tactics. The fact that Akira affiliates are targeting EDR solutions specifically1 indicates a growing awareness of the importance of these tools in detecting and preventing ransomware attacks. This development matters to security practitioners because it underscores the need for robust operational resilience planning to mitigate the impact of such attacks.
Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt
⚡ High Priority
Why This Matters
Ransomware targeting EDR highlights sector-specific risk — operational resilience planning is the real takeaway.
References
- Lawrence Abrams. (2026, August 13). Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt. *BleepingComputer*. https://www.bleepingcomputer.com/news/security/akira-hackers-disable-edr-with-safe-mode-steal-data-but-fail-to-encrypt/
Original Source
BleepingComputer
Read original →