• News/
  • https://www.bleepingcomputer.com/news/security/new-hybridpetya-ransomware-can-bypass-uefi-secure-boot/

New HybridPetya ransomware can bypass UEFI Secure Boot

BleepingComputer
·
Bill Toulas
·
Published Sep 12, 2025
·
Updated

A recently discovered ransomware strain called HybridPetya can bypass the UEFI Secure Boot feature to install a malicious application on the EFI System Partition. HybridPetya appears inspired by the destructive Petya/NotPetya malware that encrypted computers and prevented Windows from booting in attacks in 2016 and 2017 but did not provide a recovery option. Researchers at cybersecurity company ESET found a sample of HybridPetya on VirusTotal. They note that this may be a research project, a proof-of-concept, or an early version of a cybercrime tool still under limited testing. Still, ESET says that its presence is yet another example (along with BlackLotus, BootKitty, and Hyper-V Backdoor) that UEFI bootkits with Secure Bypass functionality are a real threat. HybridPetya incorporates characteristics from both Petya and NotPetya, including the visual style and attack chain of these older malware strains. However, the developer added new things like installation into the EFI System Partition and the ability to bypass Secure Boot by exploiting the CVE-2024-7344 vulnerability. ESET discovered the flaw in January this year, The issue consists in Microsoft-signed applications that could be exploited to deploy bootkits even with Secure Boot protection active on the target. Upon launch, HybridPetya determines if the host uses UEFI with GPT partitioning and drops a malicious bootkit into the EFI System partition consisting of several files. These include configuration and validation...

Read full article

Affected Software

1 affected component
ESET HybridPetya
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the newly discovered HybridPetya ransomware, which can bypass UEFI Secure Boot.

2

What security implications are discussed in the article?

The article highlights the potential for HybridPetya to install malicious applications on the EFI System Partition, compromising system security.

3

What products or software are affected by HybridPetya ransomware?

The article specifically mentions that ESET HybridPetya is an affected product.

4

How does HybridPetya ransomware differ from previous ransomware strains?

HybridPetya is noted for its ability to bypass UEFI Secure Boot, which is a significant advancement compared to earlier ransomware strains.

5

What inspired the design of HybridPetya ransomware?

HybridPetya appears to be inspired by the destructive Petya and NotPetya malware.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
New HybridPetya ransomware can bypass UEFI Secure Boot - SecAlerts