---
title: "PETYA Crypto-ransomware Overwrites MBR to Lock Users Out of Their Computers"
url: "https://thecybersecurityplace.com/petya-crypto-ransomware-overwrites-mbr-to-lock-users-out-of-their-computers/"
date: "2016-03-25T07:54:41+00:00"
section: "Software"
tags:
  - "Crypto-Ransomware"
  - "Malware"
  - "Ransomware"
  - "Software Security"
  - "Trojan"
source: "blog.trendmicro.com"
source_url: "http://blog.trendmicro.com/trendlabs-security-intelligence/petya-crypto-ransomware-overwrites-mbr-lock-users-computers/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Anti-MalwareBlog+%28Trendlabs+Security+Intelligence+Blog%29"
---

# PETYA Crypto-ransomware Overwrites MBR to Lock Users Out of Their Computers

March 25, 2016 · Reported by blog.trendmicro.com

![](https://thecybersecurityplace.com/portadas/2016/petya-crypto-ransomware-overwrites-mbr-to-lock-users-out-of-their-computers.jpg)

> As if encrypting files and holding them hostage is not enough, cybercriminals who create and spread crypto-ransomware are now resorting to causing blue screen of death (BSoD) and putting their ransom notes at system startup—as in, even before the operating system loads. Imagine turning on your computer and instead of the usual Windows icon loading, you get a flashing red and white screen with a skull-and-crossbones instead.
>
> Figure 1. Petya’s red skulls-and-crossbones warning

[Read the full article at blog.trendmicro.com](http://blog.trendmicro.com/trendlabs-security-intelligence/petya-crypto-ransomware-overwrites-mbr-lock-users-computers/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Anti-MalwareBlog+%28Trendlabs+Security+Intelligence+Blog%29)

**Tags:** [Crypto-Ransomware](https://thecybersecurityplace.com/tag/crypto-ransomware/) · [Malware](https://thecybersecurityplace.com/tag/malware/) · [Ransomware](https://thecybersecurityplace.com/tag/ransomware/) · [Software Security](https://thecybersecurityplace.com/tag/software-security/) · [Trojan](https://thecybersecurityplace.com/tag/trojan/)
