ESET Identifies HybridPetya Ransomware Bypassing UEFI Secure Boot
ESET Identifies HybridPetya Ransomware Bypassing UEFI Secure Boot

ESET Identifies HybridPetya Ransomware Bypassing UEFI Secure Boot

News summary

Researchers have identified a new ransomware strain called HybridPetya, which emulates the notorious Petya/NotPetya malware but adds advanced capabilities to compromise UEFI-based systems by exploiting the CVE-2024-7344 vulnerability to bypass UEFI Secure Boot on outdated Windows systems. Unlike NotPetya, HybridPetya acts as true ransomware by allowing victims to decrypt their files, demanding a ransom payment of $1,000 in bitcoin after encrypting the Master File Table of NTFS partitions. The malware installs a malicious EFI application to the EFI System Partition to carry out encryption and displays a fake CHKDSK status before rebooting the system. While no evidence shows HybridPetya has been deployed in the wild yet, researchers discovered its components, including bootkit variants and installers, on VirusTotal, suggesting it might be a research project or proof of concept. HybridPetya joins a limited group of real or proof-of-concept UEFI bootkits capable of evading detection by antivirus software and surviving OS reinstalls, posing a significant security threat by targeting firmware. ESET and other security firms have published detailed technical analyses of HybridPetya's operation and the Secure Boot bypass it exploits, highlighting ongoing risks to system firmware security.

Story Coverage
Bias Distribution
100% Left
Information Sources
daae85f0-2883-42fc-b085-888140adf30d
Left 100%
Coverage Details
Total News Sources
1
Left
1
Center
0
Right
0
Unrated
0
Last Updated
19 hours ago
Bias Distribution
100% Left
Related News
Daily Index

Negative

24Serious

Neutral

Optimistic

Positive

Ask VT AI
Story Coverage
Subscribe

Stay in the know

Get the latest news, exclusive insights, and curated content delivered straight to your inbox.

Present

Gift Subscriptions

The perfect gift for understanding
news from all angles.

Related News
Recommended News