Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»New hybridpetya ransomware UEFI can bypass safe boot
    Security

    New hybridpetya ransomware UEFI can bypass safe boot

    PineapplesUpdateBy PineapplesUpdateSeptember 12, 2025No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    New hybridpetya ransomware UEFI can bypass safe boot
    Share
    Facebook Twitter LinkedIn Pinterest Email

    New hybridpetya ransomware UEFI can bypass safe boot

    The recently discovered ransomware can bypass UEFI Secure Boot features to set up a malicious application on the Hybridptia EFI system division called Strain.

    Hybridptia appear to be inspired by destructive patya/NOTEPA malware that encryps the computer and prevented the windows from booting in attacks in 2016 and 2017, but did not provide a recovery option.

    Researchers at Cyber ​​Security Company ESET found a sample of hybridpetya on gerostertal. They note that this can be a research project, a proof-off-concept, or an early version of the cybercrime tool that is still under a limited trial.

    Nevertheless, ESET states that its presence is still another example (with Blackalotus, Bootcist and Hyper-V Backdor) that UEFI bootkit with safe bypass functionality is a real danger.

    Hybridptia contains the characteristics of both Petya and Notepya, including the visual style and attack chain of these olderware strains.

    However, the developer added new things such as installation in the EFI system division and the ability to bypass safe boots by exploiting CVE -2024–7344 vulnerability.

    The ESET discovered the defect in January this year, with the Microsoft-Sign Apps in the issue, which can be exploited to deploy bootkits even with safe boot protection active on the target.

    Execution logic
    Execution logic
    Source: ESET

    When launching, Hybridptia determines whether the host uses UEFI with GPT division and leaves a malicious bootkit in the EFI system division containing several files.

    These include configurations and verification files, a modified bootloader, a follow -up UEFI bootloader, an explosive payload container and a position file that tracks the encryption progress.

    The ESET lists the following files used in the analyzed variants of Hybridpetya:

    1. \ Efi \ Microsoft \ Boot \ Config
    2. \ Efi \ Microsoft \ Boot \ verified (used to validate the correct decryption key)
    3. \ Efi \ microsoft \ boot \ counter (progress tracker for encrypted cluster)
    4. \ Efi \ microsoft \ boot \ bootmgfw.efi.old (original bootloader backup)
    5. \ Efi \ microsoft \ boot \ cloak.dat

    In addition, the malware \ Efi \ Microsoft \ Boot \ Bootmgfw.efi replaces with a weak ‘Rellow -Efi’ ​​and removes \ Efi \ Boot \ Bootx64.efi.

    The original Windows bootloader is also saved to be active in a successful restoration case, meaning that the victim paid the ransom.

    Once posted, Hybridptia displays a BSOD a fake error, as Petya did, and a system forces the reboot, allowing malicious bootkits to execute the system boot.

    In this phase, the ransomware encrys all MFT clusters using a Salsa20 key and encrypse the non -extracted nonsus from the configure file when displaying fake Chkdsk messages like Notpetya.

    Fake chkdsk message
    Fake chkdsk message
    Source: ESET

    Once the encryption is completed, another reboot is triggered and the victim is served a ransom note during the system boot, seeking bitcoin payments of $ 1,000.

    Hybridpetya ransom note
    Hybridpetya ransom note
    Source: ESET

    In turn, the victim is provided a 32-ornament key that they can record on the ransom note screen, restoring the original bootloader, decrying groups, and motivating the user to reboot.

    Although Hybridpetya has not been seen in any real attack in the wild, similar projects can use it in comprehensive campaigns that target POCs and target unprotected Windows systems at any time.

    The agreement indicators to help protect this danger are provided on it. Jethb repository,

    Microsoft set the CVE-2024-7344 with a January 2025 patch on Tuesday, so Windows systems that implement it or later are protected from security updates updated hybridptia.

    Another solid exercise against ransomware is to keep the offline backup of your most important data, allowing free and easy system to be restored.


    Picus Blue Report 2025

    The passwords broke in 46% of the atmosphere, almost doubled by 25% last year.

    Picus Blue Report 2025 Now get a wider look at more conclusions on prevention, detection and data exfIs.

    boot bypass hybridpetya Ransomware safe UEFI
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHow to prepare for your latter stage now, interrupt 2025
    Next Article GR-3 Care-Bot: Gentle Robot Partner Experience
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    How a simple link allowed hackers to bypass Copilot’s security guardrails – and what Microsoft did about it

    January 19, 2026
    Startups

    Keep your PC secure when you turn it on – How to enable Secure Boot in Windows 11

    November 11, 2025
    AI/ML

    Two Apple Devices You Really Shouldn’t Buy This Month (And 9 That Are Safe For Now)

    November 1, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.