Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Akira Ransomware's Safe Mode Exploit: A New Vector for Cybercriminals




The Akira ransomware variant has been using Safe Mode to bypass endpoint detection and response (EDR) tools, employing a novel tactic to evade detection and deploy its payload. The attack highlights the evolving nature of cyber threats and the need for organizations to stay vigilant and implement robust security measures to prevent such attacks.



  • The recent discovery of Akira ransomware using Safe Mode to bypass endpoint detection and response (EDR) tools has sent shockwaves through the cybersecurity community.
  • Safe Mode, a built-in Windows feature, is being exploited by cybercriminals to bypass EDR tools and deploy ransomware.
  • The Akira ransomware attack successfully rebooted the compromised host into Safe Mode with Networking, disabling EDR tools and Defender's real-time protection.
  • The attackers exfiltrated sensitive data, which they later used to extort the victim, despite the ransomware payload failing to encrypt the endpoint.
  • The use of Safe Mode by Akira ransomware is not a new tactic, but its ability to bypass EDR tools is a significant concern for organizations.
  • Detection guidance recommends monitoring for specific indicators, including Safe Mode registry activity and remote-access tools.
  • The incident highlights the need for organizations to stay vigilant and implement robust security measures to prevent such attacks.



  • The recent discovery of Akira ransomware using Safe Mode to bypass endpoint detection and response (EDR) tools has sent shockwaves through the cybersecurity community. According to a report published by Huntress, a cybersecurity firm, the Akira ransomware variant employed a novel tactic to evade detection, leveraging the limited resources of Safe Mode to deploy its payload.

    Safe Mode, a built-in feature in Windows that loads only essential system components and drivers, is typically used to troubleshoot and repair issues with the operating system. However, cybercriminals have been exploiting Safe Mode to their advantage, using it as a means to bypass EDR tools and deploy ransomware without being detected.

    In the case of the Akira ransomware attack, the attackers successfully rebooted the compromised host into Safe Mode with Networking, which disabled the EDR tools and Defender's real-time protection. The attackers then deployed the Akira ransomware, but the payload failed to encrypt the endpoint due to memory issues caused by the limited resources of Safe Mode.

    Despite the failure, the attackers had already exfiltrated sensitive data from the compromised host, which they later used to extort the victim. The incident highlights the evolving nature of cyber threats and the need for organizations to stay vigilant and implement robust security measures to prevent such attacks.

    The use of Safe Mode by Akira ransomware is not a new tactic, as other malware variants have been exploiting this vulnerability for years. However, the Akira variant's ability to bypass EDR tools and deploy its payload in Safe Mode makes it a significant concern for organizations.

    The detection guidance provided by Huntress recommends monitoring for specific indicators, including msconfig.exe or bcdedit activity, Kernel-Boot Event ID 27 with a SAFEBOOT load option, and third-party services stopping. It also warns of remote-access tools being added to the Safe Mode service registry, which could indicate the presence of attackers planning to maintain access through the reboot.

    The incident serves as a reminder that cybersecurity is an ongoing cat-and-mouse game between attackers and defenders. As attackers continue to evolve and exploit new vulnerabilities, it is essential for organizations to stay informed and adapt their security measures to prevent such attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Akira-Ransomwares-Safe-Mode-Exploit-A-New-Vector-for-Cybercriminals-ehn.shtml

  • https://securityaffairs.com/197339/malware/akira-ransomware-uses-safe-mode-to-bypass-edr.html


  • Published: Mon Aug 17 03:06:58 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us