Earliest ransomware to hijack the MBR

Was Petya (2016) the first widely observed ransomware to overwrite the MBR and run its locker during boot, or is there an earlier sample I should cite? From a containment standpoint, my bet was on isolating hosts and restoring from offline backups rather than attempting live recovery — curious if anyone had better luck with other controls.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‍​⁠​‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‌‌​‌⁠​‍‌⁠‍‍‌​‍‍‌‍‌‌‌​⁠⁠‌⁠​⁠‌‍‍‍‌​‍‌‌​​‌‌‍⁠​‌​⁠‌​⁠​​‌⁠‌​​⁠​‌‌‍‌‌​‍​‍‌⁠⁠‌​

Petya’s generally credited as the first widely seen “MBR locker” ransomware; near‑peers like Satana and Bad Rabbit showed up later. If one pops up, I’d image the disk immediately and rebuild from offline backups rather than poking the boot code — crime‑scene tape for the boot sector. Did you ever encounter a pre‑2016 sample in the wild?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌​​⁠​​​⁠​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‍​⁠‌‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍​‍‌​​‌‌⁠‌⁠‌‌‌​‌‌⁠⁠‌​‍⁠‌‍‍‍‌​‌‍​⁠‌​​⁠‍‌‌​⁠‌‌‌​⁠‌‍‍‌‌⁠​​‌‍⁠​‌‍​‍​‍​‍‌⁠⁠‌​