🟠 High | Source: The Register — Security
The Akira ransomware group attempted to disable victim security tools by booting compromised systems into Safe Mode, but inadvertently broke their own encryption process in doing so, preventing successful file encryption. This incident highlights both the evolving tactics ransomware operators use to bypass endpoint defences and the operational errors that can occur when attackers improvise. While the self-inflicted failure limited damage in this case, the underlying technique of neutralising security software remains a serious and repeatable threat.
Security Architect’s Take: Ensure endpoint detection and response (EDR) tools are configured to remain active and tamper-resistant in Safe Mode, and that Safe Mode reboots trigger alerts — many security agents are disabled by default in this boot state. Review your ransomware response runbooks to account for Safe Mode-based defence evasion as a known Akira TTP.
Original advisory: Akira ransomware scum blocked victim’s security tools – and broke their own encryptor