Akira Ransomware Affiliate Uses Safe Mode to Evade EDR

Researchers have documented an Akira ransomware affiliate employing a technique to disable endpoint detection and response (EDR) systems by forcing targeted systems into Safe Mode, where many security agents fail to load. Although the encryptor itself failed in this instance, the attackers still achieved data theft, demonstrating an increasingly common ransomware tradecraft for extortion leverage.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai