HybridPetya is a ransomware strain that combines Petya/NotPetya-style bootlocker behavior with UEFI-focused persistence and Secure Boot bypass techniques. It was reported in 2025 and is characterized by pre-OS execution, destructive disk tampering, and modification of EFI boot components to maintain control of the system before the operating system loads.
On Windows systems, HybridPetya has been described as using an installer that decrypts an embedded DLL and executes it reflectively in memory, reducing reliance on conventional on-disk payload staging. Its payload enumerates local and remote drives, drops ransom notes across user-accessible locations, checks for administrative privileges, accesses the physical disk directly, and performs raw writes to the master boot record and other critical disk regions. It can force a crash and reboot, after which it presents a fake disk-check screen while encryption proceeds and ultimately locks the victim out at boot level with a ransom demand.
A distinguishing feature of HybridPetya is its targeting of the EFI System Partition and boot chain. It has been reported to install a malicious EFI application, replace or modify legitimate boot manager components, and thereby persist beyond normal operating system recovery workflows, including potential survival of OS reinstallation if the boot environment remains compromised. Public reporting has linked the malware to exploitation of Secure Boot bypass conditions involving vulnerable signed boot components, including CVE-2024-7344, enabling execution of untrusted code during boot on affected UEFI-based systems.
HybridPetya is primarily associated with Windows endpoints using UEFI firmware, but its abuse of EFI boot components places it in the broader category of firmware and boot-process threats. No high-confidence attribution to a specific threat actor is established in the available information. It is notable as an example of ransomware adopting bootkit-like tradecraft traditionally associated with stealthier persistence-focused malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Two CVE IDs, CVE-2026-8863 and CVE-2026-10797, cover the reported shims, and Microsoft revoked the vulnerable binaries in the dbx update shipped with its June 9 Patch Tuesday.
Two CVE IDs, CVE-2026-8863 and CVE-2026-10797, cover the reported shims, and Microsoft revoked the vulnerable binaries in the dbx update shipped with its June 9 Patch Tuesday.
Exploited vulnerability: Uses CVE-2024–7344 to bypass Secure Boot and other security protections. | HybridPetya is a new ransomware variant combining traits of Petya and NotPetya with modern firmware-targeting techniques. Discovered: Early 2025, when ESET researchers found samples on VirusTotal.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications could be abused to bypass Secure Boot on most systems using the modern firmware standard.
Attackers could bypass UEFI Secure Boot on a wide range of systems thanks to 11 Microsoft-signed UEFI shim bootloaders carrying vulnerabilities that have remained buried for more than a decade... Exploitation allows untrusted code to run during boot, opening the door to UEFI bootkits ... even with Secure Boot switched on.
Once the system reboots after the destructive payload has executed, the malware continues its deception by showing a fake CHKDSK screen.
In some execution paths, the routine also targets the EFI system partition, renaming legitimate boot manager files (bootmgfw.efi) and replacing them with its own malicious payloads.
Exploited vulnerability: Uses CVE-2024–7344 to bypass Secure Boot and other security protections.
These checks prevent wasted effort on unsuitable targets, such as small virtual drives havin disk size less than 40 mb as shown in Figure 7.
11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications could be abused to bypass Secure Boot on most systems using the modern firmware standard.
Attackers could bypass UEFI Secure Boot on a wide range of systems thanks to 11 Microsoft-signed UEFI shim bootloaders carrying vulnerabilities that have remained buried for more than a decade... Exploitation allows untrusted code to run during boot, opening the door to UEFI bootkits ... even with Secure Boot switched on.
For each valid drive, the code constructs full paths to standard directories (Desktop, Downloads, Documents, Public) and appends the fixed filename “YOUR_FILES_ARE_ENCRYPTED.TXT”.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named UEFI bootkit mentioned as malware that could be deployed if attackers bypass Secure Boot using vulnerable shim bootloaders.
A malicious UEFI bootkit mentioned as a payload that attackers could deploy once Secure Boot is bypassed.
A malicious UEFI bootkit mentioned as an example payload that could be installed once Secure Boot is bypassed.
A named UEFI bootkit mentioned as malware that attackers could deploy by leveraging vulnerable, still-trusted shim bootloaders to bypass Secure Boot.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.