According to a report by BleepingComputer, Akira ransomware affiliates have found a method to disable the Endpoint Detection and Response (EDR) solution on compromised systems.
By restarting the system into Safe Mode with Networking, these hackers are able to bypass the EDR solution, allowing them to steal data without encryption.
It is important for organizations to be aware of this tactic and take measures to secure their systems against such attacks.
À retenir
- Akira ransomware affiliates have found a method to disable EDR solutions on compromised systems.
- This is done by restarting the system into Safe Mode with Networking.
- The hackers are able to steal data without encryption due to this tactic.
Recommandations
- Organizations should be aware of this tactic and take measures to secure their systems against such attacks.
Source : BleepingComputer. Cette brève est une synthèse et une reformulation éditoriale.
