A recently discovered ransomware strain called HybridPetya can bypass the UEFI Secure Boot feature to install a malicious application on the EFI System Partition. HybridPetya appears inspired by the destructive Petya/NotPetya malware that encrypted computers and prevented Windows from booting in attacks in 2016 and 2017 but did not provide a recovery option. Researchers at cybersecurity company ESET found a sample of HybridPetya on VirusTotal. They note that this may be a research project, a proof-of-concept, or an early version of a cybercrime tool still under limited testing. Still, ESET says that its presence is yet another example (along with BlackLotus, BootKitty, and Hyper-V Backdoor) that UEFI bootkits with Secure Bypass functionality are a real threat. HybridPetya incorporates characteristics from both Petya and NotPetya, including the visual style and attack chain of these older malware strains. However, the developer added new things like installation into the EFI System Partition and the ability to bypass Secure Boot by exploiting the CVE-2024-7344 vulnerability. ESET discovered the flaw in January this year, The issue consists in Microsoft-signed applications that could be exploited to deploy bootkits even with Secure Boot protection active on the target. Upon launch, HybridPetya determines if the host uses UEFI with GPT partitioning and drops a malicious bootkit into the EFI System partition consisting of several files. These include configuration and validation...
New HybridPetya ransomware can bypass UEFI Secure Boot
BleepingComputer
·Bill Toulas
·Published Sep 12, 2025
·Updated
Affected Software
1 affected component
ESET HybridPetya
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the newly discovered HybridPetya ransomware, which can bypass UEFI Secure Boot.
2
What security implications are discussed in the article?
The article highlights the potential for HybridPetya to install malicious applications on the EFI System Partition, compromising system security.
3
What products or software are affected by HybridPetya ransomware?
The article specifically mentions that ESET HybridPetya is an affected product.
4
How does HybridPetya ransomware differ from previous ransomware strains?
HybridPetya is noted for its ability to bypass UEFI Secure Boot, which is a significant advancement compared to earlier ransomware strains.
5
What inspired the design of HybridPetya ransomware?
HybridPetya appears to be inspired by the destructive Petya and NotPetya malware.