Introducing HybridPetya: Petya/NotPetya copycat with UEFI Secure Boot bypass
ID: 5ad09021-5e02-5edb-bc56-226488c7111a
STIX ID: report--5ad09021-5e02-5edb-bc56-226488c7111a
Feed Name: WeLiveSecurity (ESET Research)
HybridPetya is a Petya/NotPetya-style ransomware discovered on VirusTotal that combines a UEFI bootkit capable of encrypting the NTFS Master File Table with installer components; a variant leverages CVE‑2024‑7344 to bypass UEFI Secure Boot by loading a malicious EFI application from a specially crafted cloak.dat. ESET's report includes technical analysis of disk encryption/decryption, installation behavior, indicators of compromise, MITRE ATT&CK mappings, and notes that there is no telemetry evidence of active widespread use at the time of writing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
