HybridPetya encrypts the Master File Table and can compromise modern UEFI-based systems by installing a malicious EFI application. A variant exploits the CVE-2024-7344 vulnerability to bypass Secure Boot with a cloak.dat file. There is no evidence of active use in the real world
Researchers of ESET, a global European leader in the cybersecurity market, have discovered a bootkit and ransomware called HybridPetya, uploaded from Poland to the malware scanning platform VirusTotal. The sample is an imitation of the infamous Petya/NotPetya; however, it adds the ability to compromise UEFI-based systems and exploit the CVE-2024-7344 vulnerability to bypass UEFI Secure Boot on out-of-date systems.
"In late July 2025, we identified suspicious ransomware samples with several filenames, including notpetyanew.exe and similar ones, that suggested a link to the highly destructive malware that hit Ukraine and numerous other countries in 2017. The NotPetya attack is believed to be the most destructive in history, with overall damage exceeding $10 billion. Because of the common characteristics between the new samples and both Petya and NotPetya, we decided to call this new HybridPetya malware,” explains Martin Smolár, ESET researcher who made the discovery.
The algorithm used to generate the victim's personal installation key, unlike the original NotPetya, allows the malware operator to reconstruct the decryption key from the victims' personal keys. In this way, HybridPetya remains usable as traditional ransomware – more like Petya. Furthermore, HybridPetya is also capable of compromising modern UEFI based systems by installing a malicious EFI application on the EFI System Partition. The deployed UEFI application is then responsible for encrypting the Master File Table (MFT) – a critical metadata file that contains information about all files on the NTFS partition.
“As we delved further into the analysis, we discovered something even more interesting on VirusTotal: an archive containing the entire contents of the EFI System Partition, including a very similar UEFI HybridPetya application, but this time integrated into a specially formatted cloak.dat file, vulnerable to CVE-2024-7344 – the UEFI Secure Boot bypass flaw that our team disclosed in early 2025,” adds Smolár. “In the ESET publications of January 2025 we had deliberately avoided providing details relating to the exploitation; it is therefore likely that the author of the malware reconstructed the correct format of the cloak.dat file through reverse engineering activities of the vulnerable application”.
ESET telemetry does not yet show any active use of HybridPetya in the real world; it could therefore be a proof of concept developed by a security researcher or an unknown actor. Furthermore, this malware does not have the aggressive network propagation capabilities of the original NotPetya.
For a more in-depth analysis and technical details on HybridPetya, the latest ESET Research article is available on the WeLiveSecurity blog: “Introducing HybridPetya: Petya/NotPetya copycat with UEFI Secure Boot bypass“. ESET Research updates can also be followed on Twitter (today X), BlueSky e Mastodon.






