New ransomware installs in boot record, encrypts hard disk

mikeymikec

Lifer
May 19, 2011
20,378
15,070
136
Out of curiosity, has anyone read whether this malware can infect Win8x/10 with secure boot enabled?
 

Elixer

Lifer
May 7, 2002
10,371
762
126
Secure boot is only for loading, so, once system boots, this malware can install a new boot loader.
Though, on some motherboards, there is a BIOS option to prevent writing to the boot sector (but, then again, the damage is already done, this malware just writes a new boot loader to display the message)
 

mikeymikec

Lifer
May 19, 2011
20,378
15,070
136
Yes, but the information about this malware suggests that it installs a new MBR, which presumably has to be UEFI compatible?