logo

HybridPetya ransomware bypasses UEFI Secure Boot echoing Petya/NotPetya

ID: 750077d3-cc56-5156-aa05-60d9f6bde69f

STIX ID: report--750077d3-cc56-5156-aa05-60d9f6bde69f

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2025-09-13

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

ESET researchers identified "HybridPetya," a Petya/NotPetya-style ransomware with a UEFI bootkit that can infect EFI system partitions and bypass UEFI Secure Boot (leveraging CVE-2024-7344 on outdated systems). The bootkit/installer encrypts the NTFS Master File Table, stores Salsa20 keys and verification blobs in the EFI partition, replaces bootloaders, and forces a reboot to execute the bootkit; while not observed actively spreading, its Secure Boot bypass and MFT encryption capabilities make it notable for future threat monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.