Akira Ransomware Reboots Windows Into Safe Mode to Disable EDR and Microsoft Defender

An Akira ransomware affiliate has been observed rebooting a compromised Windows host into Safe Mode with Networking to disable endpoint protection an anti-EDR tactic linked to the operation. The intrusion failed to encrypt files after the stripped-down boot environment triggered virtual-memory errors, but the actor had already stolen credentials and data, preserving leverage for a […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: