Just in:

HybridPetya Ransomware Breaks Secure Boot Barrier on UEFI Systems

Security researchers at ESET have identified a new malware strain called HybridPetya that combines traits of Petya and NotPetya ransomware with advanced boot-kit functionality to infect systems protected by UEFI Secure Boot. It exploits the vulnerability CVE-2024-7344 in the Howyar “Reloader” UEFI application to bypass signature checks, allowing unverified code execution.

HybridPetya was first spotted when samples uploaded to VirusTotal in February 2025 caught the eye of ESET’s threat analysts. The malware installs a malicious EFI application into the EFI System Partition, which then encrypts the Master File Table on NTFS-formatted drives. The MFT contains metadata about all files, making its encryption especially disruptive.

One variant of HybridPetya takes advantage of CVE-2024-7344 to dodge the Secure Boot mechanism. The exploit leverages a file named cloak. dat, which carries an XOR-encoded bootkit. When the vulnerable reloader. efi is executed at boot, it checks for cloak. dat on the EFI System Partition and loads its content without validating integrity, thus undermining UEFI Secure Boot protections. Systems with Microsoft’s January 2025 dbx update are said to be protected against this exploit.

HybridPetya also includes features for standard installer-based deployment. It determines whether the system uses UEFI with GUID Partition Table layout, locates the EFI System Partition, replaces or backs up legitimate bootloaders, and drops configuration, key material, and progress-tracking files into the EFI partition. A blue screen of death is triggered to force a reboot and activate the bootkit. Decryption is possible: victims supply a 32-character key, which if correct restores bootloaders and decrypts encrypted clusters.

ESET reports no evidence that HybridPetya has been used in large-scale attacks so far; there is concern that it might be a proof-of-concept or under limited testing. Analysts warn that its technical capabilities—especially Secure Boot bypass, bootkit deployment, and MFT encryption—represent a formidable escalation in ransomware threat design.

CVE-2024-7344 was disclosed in January 2025. It relates to the Howyar UEFI Application “Reloader” which permits execution of unsigned software from a hardcoded path. The vulnerability has high severity, given its impact on integrity and confidentiality.

Organisations running Windows systems with UEFI Secure Boot are urged to verify that the January 2025 “dbx” revocation list update has been applied. Systems lacking this update remain vulnerable. Security teams are also advised to monitor for indicators such as unexpected files in EFI partitions, anomalous versions of bootloader backups, or unexpected “counter” files tracking encryption status.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Inovatif Media Asia Sets Regional Ambitions in Motion with Tun Ahmad Fuzi as Strategic Advisor // India plans own orbital space outpost, second after China // Russia brings cryptocurrency market law into force // WisPaper Introduces TrueCite to Help Researchers Verify AI-Generated Academic References // Ingdan, Inc. (400.HK) Announces 2026 Interim Results // Qatar economy contracts 7% as energy output slumps // Drone strike damages Kuwait residential complex, no injuries // XcanMow Mix 2000 Robot Mower Makes Its European Debut at IFA Berlin 2026 // Jordan downs eight missiles as Iran targets US bases // The Mineral Boutique Limited Welcomes CCS Clarification and Reaffirms Asia Growth Strategy // Best Mart 360 Reports Interim Revenue Growth to HK$1.45 billion // Adobe widens Saudi AI access with $4 billion programme // What Shein’s $27bn IPO means for Mubadala // Macao Economic, Trade and Tourism Investment Promotion Seminar Held in Singapore, Deepening Multi-Domain Cooperation to Empower Regional Growth // SCX Corporation Accelerates SC Group’s Recurring-Income Businesses // Putin holds talks with Pezeshkian in Bishkek // Dubai hotel provides free public co-working space // Hong Kong Ranks Fifth Among APAC’s Preferred Living Investment Destinations as 85% of Investors Plan to Increase Sector Investment // Trump rejects munitions fears as Iran clashes resume // Hong Kong Science and Technology Parks Corporation Kicks Off 25th Anniversary Prelude “Innovation. Next by Nature.” //