logo

Introducing HybridPetya: Petya/NotPetya copycat with UEFI Secure Boot bypass

ID: 5ad09021-5e02-5edb-bc56-226488c7111a

STIX ID: report--5ad09021-5e02-5edb-bc56-226488c7111a

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
70/100

Date Published: 2025-09-12

Date Updated: 2026-05-01

...
...

HybridPetya is a Petya/NotPetya-style ransomware discovered on VirusTotal that combines a UEFI bootkit capable of encrypting the NTFS Master File Table with installer components; a variant leverages CVE‑2024‑7344 to bypass UEFI Secure Boot by loading a malicious EFI application from a specially crafted cloak.dat. ESET's report includes technical analysis of disk encryption/decryption, installation behavior, indicators of compromise, MITRE ATT&CK mappings, and notes that there is no telemetry evidence of active widespread use at the time of writing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.