Story perspectives
New HybridPetya Ransomware Targets UEFI Systems, Demands Bitcoin
9/13/2025
50 7
1 of 1
Story summary
- ESET researchers discovered HybridPetya, a ransomware strain targeting UEFI systems, similar to Petya/NotPetya.
- It exploits the Secure Boot bypass vulnerability (CVE-2024-7344) to disable security measures.
- HybridPetya encrypts the Master File Table (MFT) with the Salsa20 algorithm and shows a fake CHKDSK screen.
- Victims face a ransom demand of $1,000 in Bitcoin.
- Currently, there is no evidence of widespread deployment; it may still be in a proof-of-concept phase.
