None
EN
Introducing HybridPetya: Petya/NotPetya copycat with UEFI Secure Boot bypass
[]
WeLiveSecurity
It is a copycat of the infamous Petya/NotPetya malware, adding the capability of compromising UEFI-based systems and weaponizing CVE‑2024‑7344 to bypass UEFI Secure Boot on outdated systems.
One of the analyzed HybridPetya variants exploits CVE‑2024‑7344 to bypass UEFI Secure Boot on outdated systems, leveraging a specially crafted cloak.dat file.
We also separately dissect a version of HybridPetya that is capable of bypassing UEFI Secure Boot by exploiting CVE-2024-7344.
Also, the version deployed with the UEFI Secure Boot bypass uses a different contact email address (wowsmith999999@proton[.
D0BD283133A80B471375 62F2AAAB740FA15E6441 cloak.dat EFI/Diskcoder.A Specially formatted cloak.dat related to CVE-2024-7433, contains XORed HybridPetya UEFI bootkit component.
['boot'
'introducing'
'hybridpetya'
'petyanotpetya'
'encryption'
'uefi'
'bootkit'
'secure'
'copycat'
'system'
'bypass'
'file'
'disk'
'value'
'key']