Executive Summary
In July 2025, ESET Research uncovered HybridPetya, a proof-of-concept ransomware closely mimicking the destructive Petya and NotPetya malware. HybridPetya features a novel UEFI bootkit component, capable of targeting both legacy and modern UEFI-based systems by exploiting CVE-2024-7344 to bypass Secure Boot protections. The malware operates by encrypting the Master File Table on NTFS partitions, leveraging advanced techniques such as malicious EFI application deployment and fake CHKDSK screens to evade detection. To date, ESET’s telemetry has found no evidence of HybridPetya in active attacks, and its development suggests an evolving threat landscape for ransomware targeting core system components.
HybridPetya’s public discovery underscores an alarming trend: sophisticated ransomware is expanding its reach to firmware and boot processes, previously considered resilient to commodity malware. The rise of UEFI-targeting threats and Secure Boot bypass exploits highlights the urgent need for rigorous patch management and endpoint visibility, especially as new vulnerabilities (like CVE-2024-7344) become weaponized.
Why This Matters Now
Ransomware has moved beyond the operating system into the deepest layers of modern infrastructure—UEFI firmware. HybridPetya demonstrates that attackers can now bypass Secure Boot protections, putting almost any unpatched Windows device at risk for highly persistent and damaging attacks. Organizations must act fast to patch firmware and strengthen endpoint protections as these advanced techniques are increasingly surfacing in real-world threats.
Attack Path Analysis
HybridPetya gained initial access by delivering malicious installers capable of exploiting the UEFI Secure Boot bypass vulnerability (CVE-2024-7344) on outdated systems. The malware escalated privileges by executing a bootkit component at pre-OS boot, gaining high-level control. Lateral movement was limited but could have consisted of internal pivoting or broader propagation in multi-cloud or hybrid cloud settings. Command & Control functions were minimal, focusing on ransomware delivery and local execution rather than remote operator management, but possible beaconing or covert comms cannot be ruled out. No exfiltration of data was noted, consistent with Petya/NotPetya-style destructive ransomware, but attempted outbound comms for ransom coordination remain plausible. The ultimate impact was mass encryption of disk Master File Tables and partition metadata, preventing systems from booting until ransom payment and decryption.
Kill Chain Progression
Initial Compromise
Description
Attackers delivered HybridPetya via malicious installer files, exploiting supply chain, phishing, or vulnerable public-facing endpoints to drop the payload capable of targeting both legacy and UEFI-based hosts.
Related CVEs
CVE-2024-7344
CVSS 8.2A vulnerability in the Howyar UEFI Application 'Reloader' allows execution of unsigned software in a hardcoded path, enabling attackers to bypass UEFI Secure Boot protections.
Affected Products:
Howyar Technologies SysReturn – < 10.2.023_20240919
Greenware Technologies GreenGuard – < 10.2.023-20240927
Radix Technologies SmartRecovery – < 11.2.023-20240927
SANFONG Inc. EZ-Back System – < 10.3.024-20241127
Wasay Software Technology eRecoveryRx – < 8.4.022-20241127
Computer Education System Neo Impact – < 10.1.024-20241127
Signal Computer GmbH HDD King – < 10.3.021-20241127
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Pre-OS Boot: Bootkit
Develop Capabilities: Malware
Develop Capabilities: Exploits
Exploitation for Privilege Escalation
Exploitation for Client Execution
Exploitation for Defense Evasion
Data Encrypted for Impact
Hijack Execution Flow
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS v4.0 – User and Entity Activity Logging
Control ID: 10.1.2/10.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy and Vulnerability Management
Control ID: 500.03/500.11
DORA – Digital Operational Resilience Act – ICT Risk Management & Preventive Controls
Control ID: Art. 9(2)/Art. 14
NIS2 Directive – Security in Network and Information Systems
Control ID: Article 21(2)(e)
CISA Zero Trust Maturity Model (ZTMM) 2.0 – Device Integrity Verification
Control ID: Device Pillar: Device Security
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Health Care / Life Sciences
HybridPetya's UEFI bootkit bypassing Secure Boot poses critical risks to medical systems, potentially encrypting patient data and disrupting life-critical operations requiring HIPAA compliance.
Financial Services
Ransomware targeting UEFI systems threatens financial infrastructure integrity, with MFT encryption potentially compromising transaction systems and violating PCI compliance requirements for data protection.
Government Administration
UEFI Secure Boot bypass vulnerability exploits pose severe national security risks to government systems, potentially compromising classified data and critical infrastructure operations.
Utilities
Critical infrastructure vulnerability to bootkit attacks threatens power grid and utility control systems, potentially causing widespread service disruptions and compromising NIST cybersecurity frameworks.
Sources
- Introducing HybridPetya: Petya/NotPetya copycat with UEFI Secure Boot bypasshttps://www.welivesecurity.com/en/eset-research/introducing-hybridpetya-petya-notpetya-copycat-uefi-secure-boot-bypass/Verified
- CVE-2024-7344: Secure Boot Integrity Risks and Mitigationshttps://linuxsecurity.com/news/security-vulnerabilities/cve-2024-7344-ensuring-uefi-secure-boot-integrityVerified
- CVE-2024-7344 Impact, Exploitability, and Mitigation Stepshttps://www.wiz.io/vulnerability-database/cve/cve-2024-7344Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, policy-based egress filtering, and advanced visibility controls could have limited HybridPetya’s ability to propagate, blocked initial payload installation, and detected or constrained anomalous bootloader modifications or outbound attack communications.
Control: Cloud Firewall (ACF)
Mitigation: Prevented unauthorized installer payloads from reaching sensitive assets.
Control: Threat Detection & Anomaly Response
Mitigation: Detected abnormal activity associated with unauthorized bootloader modification or unusual access to system partitions.
Control: Zero Trust Segmentation
Mitigation: Blocked lateral movement between workloads with identity-based segmentation.
Control: Egress Security & Policy Enforcement
Mitigation: Restricted or monitored outbound C2 traffic from infected workloads.
Control: Egress Security & Policy Enforcement
Mitigation: Detected or blocked sensitive data exfiltration attempts.
Accelerated detection and response to destructive changes with centralized monitoring.
Impact at a Glance
Affected Business Functions
- IT Operations
- Data Management
- Security Monitoring
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive system configurations and user data due to unauthorized access enabled by the UEFI Secure Boot bypass.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Zero Trust Segmentation and microsegmentation to minimize blast radius from compromised endpoints and restrict lateral movement.
- • Enforce strict egress security policies and centralize application-layer firewalling to prevent outbound C2 and exfiltration activity.
- • Leverage threat detection and anomaly response to automatically surface unauthorized changes to bootloaders, configurations, or sensitive files.
- • Maintain multicloud visibility and automated audit policy enforcement over all network and identity traffic to accelerate detection and response.
- • Regularly validate asset firmware, update critical UEFI/BIOS/OS vulnerabilities, and use runtime controls to monitor for nonstandard pre-boot or installer behaviors.



