HybridPetya
HybridPetya is a Petya/NotPetya copycat ransomware variant identified by ESET as a new derivative of the Petya/NotPetya family. It is notable for targeting modern UEFI-based systems and for the ability to bypass UEFI Secure Boot by exploiting CVE-2024-7344. Reported behavior includes installing a malicious EFI application onto the EFI System Partition, enabling pre-OS compromise and firmware-level persistence. Multiple sources in the provided content describe it as capable of compromising Secure Boot and operating at the firmware level, echoing earlier Petya/NotPetya boot-impacting behavior. The malware has been referenced as an example of ransomware adopting pre-OS infection techniques previously associated with more advanced bootkits. ESET reportedly found HybridPetya samples on VirusTotal in February 2025, but the provided content states there was no evidence of in-the-wild deployment at that time. The content associates HybridPetya with ransomware activity broadly, but does not attribute it to a specific threat actor or industry-specific targeting. High-confidence indicators and artifacts mentioned include installation of a malicious EFI application on the EFI System Partition and suspicious file creation under Windows EFI boot paths such as *\EFI\Boot* and .dat files, which defenders monitor as potential signs of Secure Boot bypass or EFI tampering.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2024-7344 – Vulnerable bootloaders associated with system recovery tools were signed and distributed, enabling malware such as HybridPetya to bypass Secure Boot to install ransomware.
Recent activity
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware referenced in relation to bypassing UEFI Secure Boot.
Ransomware strain resembling Petya/NotPetya that can bypass UEFI Secure Boot using CVE-2024-7344 (per excerpt).
A new derivative of Petya/NotPetya ransomware, capable of compromising modern UEFI-based systems.
HybridPetya is a ransomware variant capable of bypassing Secure Boot, allowing it to persist and execute at the firmware level, making remediation and detection extremely difficult.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.