edr

ransomwarehigh
Akira Ransomware Uses Safe Mode to Bypass EDR
Akira ransomware operators attempted to bypass endpoint detection and response (EDR) by rebooting a compromised system into Safe Mode with Networking. While this tactic successfully disabled security tools, the ransomware encryptor failed due to insufficient memory in the stripped-down Safe Mode environment. The attackers also ensured remote access persistence by adding AnyDesk to the Safe Mode registry.

ransomware
Ransomware Affiliate Sabotages Own Attack During EDR Evasion
An affiliate attempting to deploy ransomware inadvertently disrupted its own attack by trying to evade endpoint detection and response (EDR) systems. Researchers observed the affiliate's anti-EDR measures causing the ransomware to crash before it could execute.