An Akira ransomware affiliate has been observed rebooting a compromised Windows host into Safe Mode with Networking to disable endpoint protection an anti-EDR tactic linked to the operation. The intrusion failed to encrypt files after the stripped-down boot environment triggered virtual-memory errors, but the actor had already stolen credentials and data, preserving leverage for a […]
The post Akira Ransomware Reboots Windows Into Safe Mode to Disable EDR and Microsoft Defender appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Mayura Kathir
Source: gbHackers
Source Link: https://gbhackers.com/akira-ransomware-reboots-windows/