Akira Ransomware Affiliate Exploits Safe Mode to Disable Endpoint Security, Huntress Reports

Huntress Labs Inc. has reported the first observed instance of an Akira ransomware affiliate rebooting a victim's Windows server into Safe Mode to bypass endpoint detection and response (EDR) solutions. While this technique successfully took the Huntress agent and Microsoft Defender offline, the reboot also inadvertently broke the ransomware itself, preventing encryption.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai