Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt
Summary
An Akira ransomware affiliate successfully disabled an endpoint detection and response (EDR) solution by booting a compromised system into Safe Mode with Networking. While the attackers managed to steal data from the victim, they ultimately failed to encrypt the files.
IFF Assessment
FOE
This article details a successful tactic used by ransomware actors to bypass security defenses, which is detrimental to defenders.
Defender Context
This incident highlights a critical technique attackers are using to evade EDR solutions by leveraging Safe Mode. Defenders should be aware of this tactic and implement measures to prevent unauthorized reboots into Safe Mode or monitor for such events, as it can lead to data exfiltration even if encryption is avoided.