In late July 2025, a series of ransomware appeared on VirusTotal with filenames that referenced the infamous Petya and NotPetya. Unlike its predecessors, this new threat—dubbed HybridPetya by ESET analysts—featured capabilities that extended beyond traditional user-level execution, directly targeting the UEFI firmware on vulnerable systems.

Through a specially crafted cloak.dat file and the exploitation of the CVE-2024-7344, HybridPetya manages to bypass Secure Boot on unpatched platforms and install a malicious EFI application on the EFI System Partition.
The emergence of HybridPetya marks a significant evolution in bootkit design. The malware leverages a two-component architecture: a Windows-based installer and an EFI bootkit.
See also: Hackers exploit Open-Source AdaptixC2 in attacks
During deployment, the installer locates the EFI System Partition, backs up the legitimate bootloaders, places a Salsa20-encrypted configuration file (\EFI\Microsoft\Boot\config), and places an encrypted verification array (\EFI\Microsoft\Boot\verify).
A triggered BSOD forces the system to reboot via the compromised bootloader, activating the EFI component on the next boot. ESET researchers discovered that HybridPetya supports both legacy and UEFI systems. However, its real innovation lies in bypassing UEFI Secure Boot via the CVE-2024-7344 vulnerability.
On affected systems that do not have Microsoft's January 2025 dbx update , the malicious reloader.efi application disguises itself as a trusted Microsoft-signed binary. When executed, it treats the accompanying cloak.dat file as a legitimate payload, loading and executing the XOR-obfuscated EFI bootkit without signature verification.

This technique mirrors the exploit method described by ESET in previous advisories, although it has been evolved with a ransomware framework. Once the EFI bootkit gains control, during the pre-OS phase, it reads its configuration and encryption flag. If the flag is set to “ready for encryption,” the bootkit extracts the Salsa20 key and nonce, rewrites the configuration flag, and encrypts the NTFS Master File Table (MFT) on all partitions.
See also: L7 Botnet compromised 5.76 million devices for mass attacks
During this process, a misleading CHKDSK-like progress message to the victim, covering up the malicious activity. After the encryption is complete, the system reboots, displaying a NotPetya-style ransom note.
HybridPetya: Infection Mechanism and Persistence
HybridPetya's infection mechanism relies on the interaction between the Windows installer and the UEFI bootkit. The installer starts by calling the native API NtRaiseHardError to cause a shutdown, ensuring that the malicious bootloader will be executed upon reboot.
This trick guarantees that the UEFI component will run under Secure Boot enforcement. On reboot, the EFI application locates \EFI\Microsoft\Boot\config, examines the encryption flag, and branches to the encryption or decryption logic. To decrypt, the victim must enter a 32-character key. The EFI bootkit then decrypts the verification file and, if the plaintext matches a string of 0x07 bytes, proceeds to restore the MFT and legitimate bootloaders from the .old backups.
See also: ZynorRAT targets Windows and Linux systems

By embedding this persistence directly at the firmware level, HybridPetya ensures that the ransomware cannot be removed by standard operating system-level recovery tools, increasing its resilience and making it a key threat to firmware.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The emergence of boot-level ransomware is a reminder that threats have gone “up a level”: no longer just files or processes, but the boot mechanism itself is being targeted. This changes the rules of response — a combination of immediate patches, firmware integrity checks, regular offline backups , and closer collaboration with vendors is required. Organizations must strengthen network isolation, upgrade recovery processes, and train personnel for attacks that cannot be solved by a simple reinstall.
