Malicious Windows Boot Manager Backup Created by UEFI Bootkit

PremiumReviewedSigma · High · v1
Product
windows
Category
file_event
Author
HuntRule
Published
2026-09-23
Updated
2026-09-23

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects creation of a bootmgfw.efi.old file on the EFI system partition, an artifact left when HybridPetya backs up the legitimate Windows Boot Manager before overwriting it with a malicious bootkit. Preserving the original boot manager under a .old name while hijacking the boot chain indicates pre-OS persistence and boot process tampering.

Related detections5 linkedT1542.003 — drag to rearrange
Malicious Secure Boot Bypass Files Dropped to EFI Partition
Suspicious Renamed GRUB Bootloader grubx64-real Creation via File System
Suspicious Bootkitty Rootkit Component Drop under opt via File System
Malicious Boot Configuration Tampering via bcdedit (via process_creation)
Windows bcdedit.exe Tampering for MBR/Boot Persistence (Delete, Import, SafeBoot, Network)
Malicious Windows Boot Manager Backup Created by UEFI Bootkit
Pivot detection · T1542.003 · 5 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.