HybridPetya ransomware bypasses UEFI Secure Boot echoing Petya/NotPetya
ID: 750077d3-cc56-5156-aa05-60d9f6bde69f
STIX ID: report--750077d3-cc56-5156-aa05-60d9f6bde69f
Feed Name: Security Affairs
ESET researchers identified "HybridPetya," a Petya/NotPetya-style ransomware with a UEFI bootkit that can infect EFI system partitions and bypass UEFI Secure Boot (leveraging CVE-2024-7344 on outdated systems). The bootkit/installer encrypts the NTFS Master File Table, stores Salsa20 keys and verification blobs in the EFI partition, replaces bootloaders, and forces a reboot to execute the bootkit; while not observed actively spreading, its Secure Boot bypass and MFT encryption capabilities make it notable for future threat monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
