Skip to content

Akira Ransomware Disables EDR via Windows Safe Mode

In brief: An Akira ransomware affiliate disabled EDR by rebooting into Windows Safe Mode, managing to steal data but failing to encrypt it.

An affiliate of the Akira ransomware group bypassed the EDR solution on a compromised system by rebooting the machine into Safe Mode with Networking. The attackers were able to steal data but, in this case, failed to carry out encryption.

In the incident described, an Akira affiliate used a simple but effective method: rebooting a Windows system into Safe Mode with Networking causes many EDR agents to fail to load, since these normally start as regular services during standard operation and are skipped by default in Windows’ safe state. This left the environment without active monitoring from the installed security solution, while the attackers still had network access to exfiltrate data.

For security leaders, it is relevant that this technique does not require a new vulnerability or an exploit, but instead abuses a Windows system function that is not sufficiently secured or monitored in many environments. EDR vendors have previously retrofitted protective mechanisms designed to force their agents to load even in Safe Mode; whether and to what extent these were present or configured in this specific case is not stated in the report.

What stands out about this incident is that the encryption phase of the attack failed, while data exfiltration succeeded. This suggests that detection and response capabilities remained partially effective, but the theft of sensitive data could not be prevented. For defenders, this means that reboots into Safe Mode should be treated as a warning sign and monitored — for example through log analysis of boot configuration changes (bcdedit) or through additional controls operating outside the operating system context that remain effective even when EDR is disabled.

From a response perspective, it is advisable to review policies that restrict or log boot mode changes, and to clarify with one’s own EDR vendor whether and how protection in Safe Mode is configured. In addition, network segmentation and monitoring of data exfiltration remain relevant, since in the case described, data theft occurred despite the failed encryption.


Source: www.bleepingcomputer.com · Published August 13, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: