# Akira Found a $0 EDR Bypass: Safe Mode
Windows Safe Mode exists to help you fix a broken computer. Akira ransomware affiliates have figured out it's also an excellent way to blind your security stack — and the technique is spreading.
A recently documented Akira intrusion revealed that the affiliate crippled a target's endpoint detection and response (EDR) solution without buying a zero-day, without finding an unpatched kernel vulnerability, and without any of the expensive exploit infrastructure that security vendors love to put in their marketing slides. They rebooted the machine into Safe Mode with Networking. That's it.
They exfiltrated data. The encryptor, for reasons that aren't entirely clear from the reporting, never deployed. But the evasion worked.
## Why Safe Mode Blinds Your EDR
Safe Mode is a Windows diagnostic environment that loads only the minimum drivers and services Microsoft deems essential. Most endpoint security software — CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, the whole alphabet soup — runs as third-party services that explicitly do not meet that threshold.
When a machine boots into Safe Mode, these services simply don't start. No agent, no telemetry, no behavioral analysis, no blocking. The attacker operates on what is effectively a bare OS with network access (in the "Safe Mode with Networking" variant) and no one watching.
Getting a machine to boot into Safe Mode is trivial for an attacker who already has administrator-level access — a single bcdedit command sets the flag, a reboot does the rest. Once their work is done, another bcdedit command clears it and the system boots normally on the next restart, leaving minimal artifacts of the evasion itself.
The cruel elegance here is that Safe Mode was designed to protect the system from misbehaving software. The attacker is just exploiting the fact that "misbehaving software" looks a lot like "endpoint security agent" from the OS's perspective.
## This Isn't New — It's Just More Common
Akira didn't invent this technique. AvosLocker was documented using Safe Mode to bypass EDR as far back as 2021. BlackBasta has reportedly used variants of the approach. What's changed is that the technique has filtered down from higher-tier groups to affiliates, and the affiliate ecosystem for ransomware-as-a-service means that once a tactic proves reliable, it propagates fast.
The ransomware industry is nothing if not efficient at sharing what works.
What makes the Akira case notable is the context: this affiliate managed to get past the EDR, complete a data theft phase, and then — apparently — failed on the encryption side. Double-extortion operations have made data theft the primary value driver anyway, but the failed encryption is a meaningful tell. Either the operation was interrupted, the affiliate hit a technical snag with the encryptor, or the defenders caught something after the fact. The incident report doesn't fully resolve the question, but it underscores that even a "failed" ransomware attack now constitutes a serious breach.
## What Defenders Are Actually Missing
The security industry's response to EDR bypass techniques tends to follow a predictable pattern: the vendors add a detection or prevention capability, publish a blog post, and the conversation moves on. Several EDR vendors have added Safe Mode protection in some form — Sophos, for instance, has offered tamper protection that extends into Safe Mode for years. But deployment is inconsistent, configuration often leaves gaps, and organizations running older agent versions or non-default configurations may still be exposed.
More fundamentally, the Safe Mode technique only works if the attacker already has local administrator access. That prerequisite doesn't get enough attention. By the time someone is rebooting your server into Safe Mode, you've already lost the initial access battle. The questions worth asking are:
The technique is interesting, but it's a symptom. Hardening privileged access, implementing credential tiering, and actually reviewing EDR agent coverage (not just license counts) address the conditions that make Safe Mode tricks possible.
## The Affiliate-Model Problem
Akira operates as ransomware-as-a-service, meaning the group maintains the malware and infrastructure while affiliates — independent contractors, essentially — carry out the actual intrusions. This model has produced a consistent pattern: the sophistication of individual attacks is highly variable, determined by whatever affiliate happened to pick up the job.
The affiliate who hit this target knew about the Safe Mode bypass. That knowledge is no longer a differentiator for sophisticated actors — it's general curriculum. Any affiliate researching pre-attack preparation is going to encounter it. The fact that the encryptor failed despite a successful evasion and exfiltration phase is actually consistent with the affiliate model: data theft tooling tends to be more reliable and better documented than the encryption deployment, which often requires more coordination with the core group.
Akira has been active since at least 2023, targeting primarily small-to-midsize businesses across manufacturing, finance, and professional services. The group is known for moving quickly once inside a network and for prioritizing data theft as leverage even when encryption succeeds.
---
## HackWire Analysis
The Safe Mode EDR bypass deserves more sustained attention than it typically gets, because it exposes a structural weakness in how organizations think about endpoint security coverage.
Most enterprises measure EDR deployment in terms of installed agents and license compliance. What they often don't track is whether those agents are configured with tamper protection enabled, whether Safe Mode protection is active (not all vendors offer it, and those that do frequently don't have it on by default), and whether their EDR telemetry pipeline would even detect a Safe Mode reboot as an anomalous event.
The Akira incident is a useful test case: if your SOC received a Windows event log entry showing a bcdedit modification to the boot configuration followed by a reboot, would that trigger an alert? It should. Safe Mode reboots on production servers are not normal operational behavior. The reboot itself is a detection opportunity that requires no EDR agent to catch — it just requires someone to have configured their SIEM to care about it.
This points to a broader theme in ransomware defense that gets underemphasized: detection layering. Any environment where the EDR is the last line of defense is already in trouble. Network-based detection, Windows event log monitoring, privileged access workstation controls, and credential auditing all operate independently of whether an endpoint agent is running — and collectively they create the overlapping coverage that makes single-point bypasses far less catastrophic.
The timing also matters. We're seeing Safe Mode techniques proliferate across RaaS affiliate networks right as organizations are becoming more confident in their EDR investments. That confidence is partly warranted, but it can create blind spots. The attackers are betting that defenders assume EDR coverage means comprehensive coverage. In Safe Mode, it means nothing at all.
Defenders in the manufacturing and professional services sectors — Akira's primary hunting ground — should treat this as a configuration audit trigger, not just an intelligence report.
— HackWire Editorial
---
## Related Coverage