By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
AdkhabarAdkhabarAdkhabar
Notification Show More
Font ResizerAa
  • Home
  • Automobile
  • Entertainment
  • Esports
  • Food
  • Health
  • Life Style
  • News
  • Technology
  • Travel
Reading: ESET Research discovers UEFI-compatible HybridPetya ransomware capable of Secure Boot bypass
Share
Font ResizerAa
AdkhabarAdkhabar
  • Home
  • Automobile
  • Entertainment
  • Esports
  • Food
  • Health
  • Life Style
  • News
  • Technology
  • Travel
Search
  • Home
  • Automobile
  • Entertainment
  • Esports
  • Food
  • Health
  • Life Style
  • News
  • Technology
  • Travel
Follow US
Adkhabar > Blog > Technology > ESET Research discovers UEFI-compatible HybridPetya ransomware capable of Secure Boot bypass
ESET Research discovers UEFI-compatible HybridPetya ransomware capable of Secure Boot bypass
Technology

ESET Research discovers UEFI-compatible HybridPetya ransomware capable of Secure Boot bypass

GlobeNews Wire
Last updated: 14/09/2025 8:38 AM
GlobeNews Wire
Published: 14/09/2025
Share
SHARE
  • ESET Research has discovered new ransomware samples, which it has named HybridPetya, resembling the infamous Petya/NotPetya malware. They were uploaded to VirusTotal in February 2025.
  • HybridPetya encrypts the Master File Table, which contains important metadata about all the files on NTFS-formatted partitions.
  • Unlike the original Petya/NotPetya, HybridPetya can compromise modern UEFI-based systems by installing a malicious EFI application onto the EFI System Partition.
  • One of the analyzed HybridPetya variants exploits CVE-2024-7344 to bypass UEFI Secure Boot on outdated systems, leveraging a specially crafted cloak.dat file.
  • ESET telemetry shows no signs of HybridPetya being used in the wild yet.

BRATISLAVA, Slovakia, Sept. 12, 2025 (GLOBE NEWSWIRE) — ESET Research has discovered a HybridPetya bootkit and ransomware uploaded from Poland to the malware-scanning platform VirusTotal. The sample is a copycat of the infamous Petya/NotPetya malware; however, it adds the capability of compromising UEFI-based systems and weaponizing CVE-2024-7344 to bypass UEFI Secure Boot on outdated systems.

“Late in July 2025, we encountered suspicious ransomware samples under various filenames, including notpetyanew.exe and other similar ones, suggesting a connection with the infamously destructive malware that struck Ukraine and many other countries back in 2017. The NotPetya attack is believed to be the most destructive cyberattack in history, with more than $10 billion in total damages. Due to the shared characteristics of the newly discovered samples with both Petya and NotPetya, we named this new malware HybridPetya,” says ESET researcher Martin Smolár, who made the discovery.

The algorithm used to generate the victim’s personal installation key, unlike in the original NotPetya, allows the malware operator to reconstruct the decryption key from the victim’s personal installation keys. Thus, HybridPetya remains viable as regular ransomware – more like Petya. Additionally, HybridPetya is also capable of compromising modern UEFI-based systems by installing a malicious EFI application to the EFI System Partition. The deployed UEFI application is then responsible for encryption of the NTFS-related Master File Table (MFT) file – an important metadata file containing information about all the files on the NTFS-formatted partition.

“After a bit more digging, we discovered something even more interesting on VirusTotal: an archive containing the whole EFI System Partition contents, including a very similar HybridPetya UEFI application, but this time bundled in a specially formatted cloak.dat file, vulnerable to CVE-2024-7344 – the UEFI Secure Boot bypass vulnerability that our team disclosed in early 2025,” adds Smolár. ESET publications from January 2025 purposely refrained from detailing the exploitation; thus, the malware author probably reconstructed the correct cloak.dat file format based on reverse engineering the vulnerable application on their own.

ESET telemetry shows no active use of HybridPetya in the wild yet; thus, HybridPetya may just be a proof of concept developed by a security researcher or an unknown threat actor. Furthermore, this malware does not exhibit the aggressive network propagation seen in the original NotPetya.

For a more detailed analysis and technical breakdown of HybridPetya, check out the latest ESET Research blogpost Introducing HybridPetya: Petya/NotPetya copycat with UEFI Secure Boot bypass on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

About ESET
ESET® provides cutting-edge cybersecurity to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown— securing businesses, critical infrastructure, and individuals. Whether it’s endpoint, cloud, or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit www.eset.com or follow our social media, podcasts and blogs.



CHCNAV Engages Agritechnica 2025, Full-Stack Precision Agriculture Solution Sparks Global Partnership Interest
INTRODUCING THE STAR OF STAR OF THE SEAS: ROYAL CARIBBEAN NAMES DIANA ROSS GODMOTHER
Shanghai Electric Powers Up Iraq’s Energy Future with Major 625MW Efficiency Upgrade
Keypoint Intelligence’s Deborah Hawkins to Speak at RemaxWorld Expo 2025
Bybit Unveils 1H 2025 Report: A Masterclass in Crisis Response, AI-Driven Innovation, and Market Leadership
TAGGED:bootbypasscapablediscoversesethybridpetyanewsransomwareResearchsecureuefi-compatible
Share This Article
Facebook Email Print
- Advertisement -

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

Weekly Newsletter

Subscribe to our newsletter to get our newest articles instantly!
Popular News
Alchera X Advances Industry Leadership with Executive Feature in Leading Technology Publication during CES 2026 in Las Vegas
Technology

Alchera X Advances Industry Leadership with Executive Feature in Leading Technology Publication during CES 2026 in Las Vegas

GlobeNews Wire
GlobeNews Wire
09/01/2026
UN Global Compact Launches Central Asia Network to Drive SDG Progress
Automation Anywhere Announces Availability of Agents in the New AWS Marketplace AI Agents and Tools Category
e-Contact Receives Frost & Sullivan’s 2025 Latin American Contact Center Solutions Customer Value Leadership Recognition for Excellence in Innovation and Customer Engagement
Floe Health Launches to Power Intelligence at Every Patient Touchpoint
- Advertisement -
- Advertisement -
- Advertisement -

Categories

  • Automobile
  • Entertainment
  • E-Sports
  • Food
  • Health
  • Technology
  • LifeStyle
  • Travel

About Us

Through our news networks, we raise millions of users' awareness. We are among the world's most reputable news networks.
Quick Link
Top Categories
  • Entertainment

Subscribe US

Subscribe to our newsletter to get our newest articles instantly!

AdkhabarAdkhabar
Copyright © 2021 - 2025 AdKhabar. All Rights Reserved. POWERED BY Life Care News.
Join Us!
Subscribe to our newsletter and never miss our latest news, podcasts etc..
Zero spam, Unsubscribe at any time.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?