How Akira's Safe Mode Trick Disables Endpoint Protection
A new tactic from an Akira ransomware affiliate is drawing attention from security researchers: rebooting a compromised Windows machine into Safe Mode with Networking as a way to strip away endpoint defenses before deploying the payload. The move is simple but effective. Once inside a victim's network, the attacker forces the infected host to restart into Safe Mode, a diagnostic environment that loads only the core Windows drivers and services needed to run the operating system.
That stripped-down environment is exactly the point. Most third-party security software, including endpoint detection and response (EDR) tools and Microsoft Defender, isn't designed to load in Safe Mode. These products typically depend on services, drivers, and startup processes that Windows intentionally excludes when it boots into this limited troubleshooting state. By the time the machine finishes rebooting, the very tools meant to catch and block ransomware activity are effectively offline, giving the attacker a clear runway to disable protections further or move toward encryption.
The Safe Mode with Networking option is notable because it still gives the attacker internet or local network access while keeping most security agents dormant. It's a deliberate choice that balances stealth with functionality, letting the affiliate continue operating inside the environment without tripping the alarms that a fully protected system would normally raise.
Why Antivirus and EDR Alone Aren't Enough
This incident is a pointed reminder that endpoint security products, no matter how advanced, are not invincible. EDR and antivirus software are built to monitor and respond to threats within the normal operating environment of Windows. When an attacker can manipulate the boot process itself, those tools lose their footing entirely.
It's a classic example of attackers targeting the gaps between security layers rather than trying to defeat a product head-on. Rather than attempting to disable Defender or an EDR agent while it's actively running and monitored, the affiliate simply removed the environment those tools depend on. This kind of boot-level maneuver sits outside what most endpoint products are designed to detect, which is why relying on a single control, even a well-regarded one, leaves organizations exposed.
Defense-in-Depth: Backups, Network Segmentation, and Monitoring
The lesson here isn't that endpoint protection is worthless. It's that it needs to be one layer among several. Organizations that weather ransomware incidents with minimal damage tend to have redundancy built into their security posture rather than a single point of failure.
Offline or immutable backups remain one of the most reliable safeguards against ransomware, since they let a business recover data without needing to interact with attackers at all. Network segmentation limits how far an intruder can travel once they gain a foothold, reducing the blast radius of any single compromised machine. And centralized logging or monitoring that operates independently of the endpoint itself, such as network traffic analysis or centralized event collection, can catch suspicious reboots, authentication attempts, or lateral movement even when local security agents have been sidelined.
Multi-factor authentication and strict access controls also matter, since most ransomware operators still need some form of initial access before they can attempt tricks like this one. Closing off those entry points reduces the number of opportunities an affiliate has to reach the point where disabling EDR even becomes relevant.
What This Means for the Broader Ransomware Threat Landscape
Akira has been one of the more active and adaptable ransomware operations in recent years, and tactics like this Safe Mode maneuver show that affiliates are continuing to refine how they evade modern defenses. As security vendors improve detection within the standard Windows environment, attackers are increasingly looking for ways to step outside it altogether. That's a trend worth watching, since it suggests future ransomware campaigns may lean more heavily on boot-level or pre-operating-system tricks rather than trying to out-maneuver EDR in real time.
Interestingly, this same Safe Mode approach hasn't always gone smoothly for Akira's affiliates. In an earlier incident covered by vpn.social, Akira ransomware's Safe Mode move backfired on attackers, when a misstep in execution ended up sabotaging the attack instead of helping it succeed. That earlier case is a useful counterpoint: even a clever bypass technique can fail when ransomware operators rush their own playbook.
What This Means For You
For everyday users, this news reinforces a familiar but important point: no single tool, including Microsoft Defender or a premium EDR product, guarantees full protection against ransomware. For IT and security teams, it's a call to test how your organization would detect or respond to a sudden reboot into Safe Mode, since that kind of anomaly should be treated as a red flag rather than routine maintenance.
Actionable takeaways:
- Maintain offline or immutable backups that don't rely on network connectivity to stay safe from encryption.
- Monitor for unexpected reboots into Safe Mode, especially outside of scheduled maintenance windows.
- Segment networks so a single compromised endpoint can't easily reach critical systems.
- Enforce multi-factor authentication and strong access controls to reduce the odds of attackers gaining a foothold in the first place.
- Treat endpoint protection as one layer of defense, not the entire strategy, and pair it with network-level monitoring and incident response planning.




