Researchers at cybersecurity firm ESET have identified a new ransomware called HybridPetya , which bears similarities to the notorious Petya and NotPetya malware . Like its predecessors, the malware targets the Master File Table (MFT) — a central database on NTFS partitions that records all files and directories. However, according to ESET, HybridPetya can bypass UEFI Secure Boot to install a malicious application on the EFI system partition .
See also: Hidden connections between Ransomware groups

There is also another difference: While NotPetya aims “only” to destroy data, HybridPetya acts as a real ransomware. According to the researchers, the algorithm it contains allows attackers to reconstruct the decryption key from the victim’s personal installation key. Theoretically, this could allow victims to recover their data after paying a ransom. The variant analyzed by ESET demanded 850 euros in Bitcoin.
However, ESET researchers suspect that this is a research project, a PoC, or an early version of a cybercrime tool that is still in the limited testing phase.
See also: Everest ransomware: Hackers say they breached BMW

How the attack works
According to ESET, the ransomware exploits a previously patched vulnerability (CVE-2024-7344) in a signed Microsoft EFI file (reloader.efi). It then loads an unsigned malicious file called cloak.dat. This bypasses integrity checks and allows the malware to execute even before the operating system starts.
The installer replaces the legitimate Windows boot loader with the vulnerable version. The malware then intentionally causes the system to crash, forcing a reboot. Upon boot, the compromised boot loader launches the HybridPetya bootkit and begins encrypting the MFT.
Encryption with the Salsa20 algorithm renders the entire hard drive unreadable. A fake CHKDSK message is used to cover up the malicious activity.
See also: Insight Partners reports ransomware attack

Although the HybridPetya ransomware has not yet been observed in active use, it should be considered a warning of a new generation of bootkit-based threats.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
