HybridPetya Ransomware Exploits CVE-2024-7344 to Bypass UEFI Secure Boot
HighWhat happened
A new ransomware variant named HybridPetya has been identified, capable of bypassing UEFI Secure Boot by exploiting the CVE-2024-7344 vulnerability. This malware installs a malicious application on the EFI System Partition, encrypts the Master File Table (MFT), and demands a ransom for decryption.
Who is affected
Organizations and individuals using Windows systems with outdated UEFI firmware that have not applied the January 2025 security updates are at risk.
Why it matters
HybridPetya's ability to bypass Secure Boot and encrypt critical system files poses a significant threat, potentially rendering systems inoperable and leading to data loss or operational disruptions.
How it could have been prevented
Applying the January 2025 security updates that address CVE-2024-7344 and maintaining regular offline backups of critical data can mitigate the risk posed by such ransomware.
Relevant professional terms
- UEFI Secure Boot
- A security standard designed to ensure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM).
- EFI System Partition (ESP)
- A partition on a data storage device that is used by computers adhering to the UEFI specification for booting operating systems and other utilities.
Recommended reading: BleepingComputer
