<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Akira on CuraSec</title><link>https://curasec.metacog.co.kr/tags/akira/</link><description>Recent content in Akira on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 14 Aug 2026 11:54:18 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/akira/index.xml" rel="self" type="application/rss+xml"/><item><title>Akira ransomware evades EDR by rebooting victim into Safe Mode</title><link>https://curasec.metacog.co.kr/insights/2026-08-14-akira-hackers-disable-edr-with-safe-mode-steal-data-but-fail/</link><pubDate>Fri, 14 Aug 2026 11:54:18 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-14-akira-hackers-disable-edr-with-safe-mode-steal-data-but-fail/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Verify your EDR agent is configured to load and protect in Safe Mode, and audit whether bcdedit or safeboot registry keys can be modified by non-admin processes — most EDR platforms have a specific setting for this that is not always on by default.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Hunt for bcdedit commands setting safeboot (T1562.001) and unexpected Safe Mode reboots in Windows event logs since Akira affiliates actively use this to blind EDR before data theft; tune alerts on bcdedit execution from unexpected parent processes.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Akira affiliates are successfully exfiltrating data even when encryption fails, confirming that ransomware incidents now carry extortion risk independent of operational disruption — worth a note in the next risk-register review.&lt;/li>
&lt;/ul></description></item></channel></rss>