HomeSecurityRansomware HybridPetya: Is it different from Petya and NotPetya?

HybridPetya Ransomware: Is it Different from Petya and NotPetya?

Researchers at cybersecurity firm ESET have identified a new ransomware called HybridPetya , which bears similarities to the notorious Petya and NotPetya malware . Like its predecessors, the malware targets the Master File Table (MFT) — a central database on NTFS partitions that records all files and directories. However, according to ESET, HybridPetya can bypass UEFI Secure Boot to install a malicious application on the EFI system partition .

See also: Hidden connections between Ransomware groups

HybridPetya

There is also another difference: While NotPetya aims “only” to destroy data, HybridPetya acts as a real ransomware. According to the researchers, the algorithm it contains allows attackers to reconstruct the decryption key from the victim’s personal installation key. Theoretically, this could allow victims to recover their data after paying a ransom. The variant analyzed by ESET demanded 850 euros in Bitcoin.

However, ESET researchers suspect that this is a research project, a PoC, or an early version of a cybercrime tool that is still in the limited testing phase.

See also: Everest ransomware: Hackers say they breached BMW

HybridPetya Ransomware: Is it Different from Petya and NotPetya?

How the attack works

According to ESET, the ransomware exploits a previously patched vulnerability (CVE-2024-7344) in a signed Microsoft EFI file (reloader.efi). It then loads an unsigned malicious file called cloak.dat. This bypasses integrity checks and allows the malware to execute even before the operating system starts.

The installer replaces the legitimate Windows boot loader with the vulnerable version. The malware then intentionally causes the system to crash, forcing a reboot. Upon boot, the compromised boot loader launches the HybridPetya bootkit and begins encrypting the MFT.

Encryption with the Salsa20 algorithm renders the entire hard drive unreadable. A fake CHKDSK message is used to cover up the malicious activity.

See also: Insight Partners reports ransomware attack

HybridPetya Ransomware: Is it Different from Petya and NotPetya?

Although the HybridPetya ransomware has not yet been observed in active use, it should be considered a warning of a new generation of bootkit-based threats.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS