
The approach is not entirely new. Huntress pointed to ransomware families, including Snatch and AvosLocker, that have used Safe Mode to disable defenses for years. MITRE ATT&CK tracks the behaviour as T1688, impair Defenses: Safe Mode Boot.
Akira picking up the technique now aligns with its recent attempts to operate outside EDR coverage. Earlier this year, an Akira affiliate was reported creating a new virtual machine on a victim’s hypervisor specifically to run the encryptor where Huntress was not installed.
The anti-EDR move accidentally stopped the ransomware
The technique, however, did not produce the outcome the attacker wanted, Northey noted. After “akira.exe” launched in Safe Mode, the system began reporting virtual memory failures. Huntress observed “Virtual Memory Minimum Too Low” and “Out of Virtual Memory” errors, followed by PowerShell failures.
