Back to News
Market Impact: 0.5

ESET Research discovers UEFI-compatible HybridPetya ransomware capable of Secure Boot bypass

Cybersecurity & Data PrivacyTechnology & Innovation

ESET Research has identified HybridPetya, a sophisticated new ransomware variant discovered in February 2025, which significantly advances on the destructive Petya/NotPetya malware. This threat can compromise modern UEFI-based systems and exploits CVE-2024-7344 to bypass UEFI Secure Boot, encrypting the Master File Table. While not yet detected in the wild, its design for decryption key reconstruction makes it viable ransomware, posing a substantial future cybersecurity risk for enterprises and potentially causing significant operational and financial disruption, echoing the $10 billion impact of NotPetya.

Analysis

ESET Research has identified a new ransomware strain, HybridPetya, which represents a significant evolution of the destructive Petya/NotPetya malware that caused over $10 billion in damages in 2017. Discovered on VirusTotal in February 2025, this malware is distinguished by its ability to compromise modern UEFI-based systems, a capability its predecessors lacked. Notably, one variant weaponizes the CVE-2024-7344 vulnerability to bypass UEFI Secure Boot, demonstrating a high level of technical sophistication by its creators, who likely reverse-engineered the exploit. Unlike the purely destructive NotPetya, HybridPetya is designed as a viable ransomware tool, as its architecture allows operators to reconstruct decryption keys, creating a direct financial incentive for its deployment. While ESET telemetry confirms the malware has not yet been observed in active campaigns, its existence signals a potent and latent threat to enterprise IT infrastructure, capable of causing severe operational disruption by encrypting the Master File Table (MFT).

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo

Market Sentiment

Overall Sentiment

strongly negative

Sentiment Score

-0.70

Key Decisions for Investors

  • The emergence of advanced, UEFI-targeting threats like HybridPetya reinforces the secular growth thesis for the cybersecurity sector; consider increasing exposure to companies specializing in endpoint security, threat intelligence, and firmware protection.
  • Investors should assess the cybersecurity resilience of portfolio companies, particularly in sectors vulnerable to operational disruption like logistics and manufacturing, as a future HybridPetya attack could have a material financial impact comparable to the NotPetya event.
  • Given that the malware is not yet 'in the wild,' the primary catalyst remains its first detection in an active campaign, which would likely trigger increased volatility and a flight to quality within the cybersecurity space.