Skip to content

ESET Research discovers UEFI-compatible HybridPetya ransomware capable of Secure Boot bypass

  • ESET Research has discovered new ransomware samples, which it has named HybridPetya, resembling the infamous Petya/NotPetya malware. They were uploaded to VirusTotal in February 2025.
  • HybridPetya encrypts the Master File Table, which contains important metadata about all the files on NTFS-formatted partitions.
  • Unlike the original Petya/NotPetya, HybridPetya can compromise modern UEFI-based systems by installing a malicious EFI application onto the EFI System Partition.
  • One of the analyzed HybridPetya variants exploits CVE-2024-7344 to bypass UEFI Secure Boot on outdated systems, leveraging a specially crafted cloak.dat file.
  • ESET telemetry shows no signs of HybridPetya being used in the wild yet.

BRATISLAVASeptember 12, 2025 — ESET Research has discovered a HybridPetya bootkit and ransomware uploaded from Poland to the malware-scanning platform VirusTotal. The sample is a copycat of the infamous Petya/NotPetya malware; however, it adds the capability of compromising UEFI-based systems and weaponizing CVE-2024-7344 to bypass UEFI Secure Boot on outdated systems.

“Late in July 2025, we encountered suspicious ransomware samples under various filenames, including notpetyanew.exe and other similar ones, suggesting a connection with the infamously destructive malware that struck Ukraine and many other countries back in 2017. The NotPetya attack is believed to be the most destructive cyberattack in history, with more than $10 billion in total damages. Due to the shared characteristics of the newly discovered samples with both Petya and NotPetya, we named this new malware HybridPetya,” says ESET researcher Martin Smolár, who made the discovery.

The algorithm used to generate the victim’s personal installation key, unlike in the original NotPetya, allows the malware operator to reconstruct the decryption key from the victim’s personal installation keys. Thus, HybridPetya remains viable as regular ransomware – more like Petya. Additionally, HybridPetya is also capable of compromising modern UEFI-based systems by installing a malicious EFI application to the EFI System Partition. The deployed UEFI application is then responsible for encryption of the NTFS-related Master File Table (MFT) file – an important metadata file containing information about all the files on the NTFS-formatted partition.

“After a bit more digging, we discovered something even more interesting on VirusTotal: an archive containing the whole EFI System Partition contents, including a very similar HybridPetya UEFI application, but this time bundled in a specially formatted cloak.dat file, vulnerable to CVE-2024-7344 – the UEFI Secure Boot bypass vulnerability that our team disclosed in early 2025,” adds Smolár. ESET publications from January 2025 purposely refrained from detailing the exploitation; thus, the malware author probably reconstructed the correct cloak.dat file format based on reverse engineering the vulnerable application on their own.

ESET telemetry shows no active use of HybridPetya in the wild yet; thus, HybridPetya may just be a proof of concept developed by a security researcher or an unknown threat actor. Furthermore, this malware does not exhibit the aggressive network propagation seen in the original NotPetya.

For a more detailed analysis and technical breakdown of HybridPetya, check out the latest ESET Research blogpost: “Introducing HybridPetya: Petya/NotPetya copycat with UEFI Secure Boot bypass,” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

Overview of HybridPetya’s execution logic

 

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET named a Strong Performer in independent evaluation of MDR services in Europe

BRATISLAVASeptember 4, 2025 — ESET, a global leader in cybersecurity, has been named a Strong Performer in The Forrester Wave™: Managed Detection And Response Services In Europe, Q3 2025. ESET believes this recognition underscores the strength of its ESET PROTECT Platform, which powers its Managed Detection and Response (MDR) services by combining regional threat intelligence with extended detection and response (XDR) capabilities.

According to the report,1 “ESET leverages its Central and Eastern European presence to source highly localized threat intelligence to deliver MDR services. ESET has maintained trust by focusing on endpoint maturity and regional compliance, including dedicated EU tenancy and sovereign operations. Reference customers highlighted ESET’s transparency and hands-on support, noting local language capabilities and threat advisories as positive traits. Organizations with a significant endpoint landscape looking for strong regional threat intelligence should consider ESET.”

In line with Forrester’s focus on sovereignty, speed, and response maturity, ESET’s strategy highlights its strength in localized threat intelligence and commitment to EU regulatory compliance. Built on a robust foundation in endpoint security, ESET is further distinguished by its transparency, hands-on support, and deep regional presence.

“We are proud to be recognized a Strong Performer in Forrester’s evaluation of MDR services in Europe,” said Michal Jankech, Vice President, Enterprise & SMB/MSP, at ESET. “For us, this acknowledgment reflects our commitment to delivering high-quality, regionally attuned cybersecurity services that meet the evolving needs of European organizations. Our ESET PROTECT Platform continues to evolve, combining deep endpoint expertise with extended detection and response to help customers stay resilient in the face of complex threats. We remain dedicated to continuous innovation and progress, with a clear focus on further enhancing our MDR capabilities to meet future challenges.”

European CISOs increasingly rely on MDR providers not only for faster threat detection but also to maintain operational resilience amid regulatory, economic, and cybersecurity challenges. With mandates such as NIS2 and DORA, and a growing shortage of skilled professionals, MDR services must offer localized support, mature response capabilities, and compliance-driven data sovereignty.

ESET believes this recognition validates its strategic focus on regional threat visibility, trusted support, and compliance-first MDR delivery — all essential for organizations navigating today’s regulatory and threat landscape.

1The Forrester Wave™: Managed Detection And Response Services In Europe, Q3 2025. Tope Olufon with Jinan Budge, Angela Lozada, Bill Nagel. September 3, 2025

Discover more about ESET MDR services and our XDR-enabling solution.

Find out how ESET helps businesses comply with cyber insurance and regulations.

Forrester does not endorse any company, product, brand, or service included in its research publications and does not advise any person to select the products or services of any company or brand based on the ratings included in such publications. Information is based on the best available resources. Opinions reflect judgment at the time and are subject to change. For more information, read about Forrester’s objectivity here.

 

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET discovers PromptLock, the first AI-powered ransomware

  • ESET Research discovers PromptLock, a new type of ransomware using GenAI to execute attacks.
  • The malware runs a locally accessible AI language model to generate malicious Lua scripts in real time, which are compatible across Windows, Linux, and macOS.
  • PromptLock uses a freely available language model accessed via an API, meaning the generated malicious scripts are served directly to the infected device.
  • Based on predefined text prompts, PromptLock autonomously determines whether to exfiltrate or encrypt data.
  • While ESET considers PromptLock a proof of concept, the threat it represents is very real.

BRATISLAVAAugust 27, 2025 — ESET researchers have uncovered a new type of ransomware that leverages generative artificial intelligence (GenAI) to execute attacks. Named PromptLock, the malware runs a locally accessible AI language model to generate malicious scripts in real time. During infection, the AI autonomously decides which files to search, copy, or encrypt — marking a potential turning point in how cybercriminals operate.

“The emergence of tools like PromptLock highlights a significant shift in the cyber threat landscape,” said Anton Cherepanov, senior malware researcher at ESET, who analyzed the malware alongside fellow researcher Peter Strýček.

PromptLock creates Lua scripts that are compatible across platforms, including Windows, Linux, and macOS. It scans local files, analyzes their content, and — based on predefined text prompts — determines whether to exfiltrate or encrypt the data. A destructive function is already embedded in the code, though it remains inactive for now.

The ransomware uses the SPECK 128-bit encryption algorithm and is written in Golang. Early variants have already surfaced on the malware analysis platform VirusTotal. While ESET considers PromptLock a proof of concept, the threat it represents is very real.

“With the help of AI, launching sophisticated attacks has become dramatically easier — eliminating the need for teams of skilled developers,” added Cherepanov. “A well-configured AI model is now enough to create complex, self-adapting malware. If properly implemented, such threats could severely complicate detection and make the work of cybersecurity defenders considerably more challenging.”

PromptLock uses a freely available language model accessed via an API, meaning the generated malicious scripts are served directly to the infected device. Notably, the prompt includes a Bitcoin address reportedly linked to Bitcoin creator Satoshi Nakamoto.

ESET has published technical details to raise awareness within the cybersecurity community. The malware has been classified as Filecoder.PromptLock.A.

Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

 

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Pens up, brains on! 5 common back-to-school online scams

Back-to-school remains a popular period for scammers trying to steal money and data from both parents and students alike. However, things are trending for the worse with advanced tools, particularly AI and deepfakes. Now these attacks can be produced more easily and quickly, on a larger scale, and fraudulent content is increasingly believable.

On top of that, scammers often focus on smartphones as a combination of smaller screen size and the convenience of phone use makes, for example, phishing attacks four times more successful.  

For students, and for parents of minors, this highlights the necessity of understanding the new tricks scammers have up their sleeves, and the need for reliable cybersecurity protection capable of stopping attacks in their early stages before any data or finances are lost.

 

Scams to watch out for

So, let’s look at some of the most common scams targeting smartphone users during the back-to-school season:

Phishing – A school needs your details, now!

Attackers try to deceive individuals into downloading malware or revealing their sensitive information mostly via messages that appear to be from a trusted institution or person, which create a false sense of urgency to prompt the targeted victims to act quickly.

In the context of the back-to-school period, scammers often try to impersonate school representatives, for example, communicating that targeted students are eligible for financial aid, or that their school accounts have expired.

Delivery scams – Your delivery failed to arrive!

Expecting higher online shopping activity, scammers may send fraudulent messages pretending to be from legitimate delivery service providers. Usually, they claim that a delivery has failed, and that either your personal/financial information or payment of a small fee is required. Delivery scam messages may also contain a link for downloading a parcel tracking app, which is, in fact, malware.

Online shopping scams – You won’t find better prices!

Scammers often create entire fake, but believable, online shops or copycats of legitimate online markets to trick visitors into buying non-existent or fake products, such as clothes, electronics, or school supplies. Of course, these feature the usual great discounts and too-good-to-be-true offers needed to entice potential victims.

ESET researchers have documented advanced variations of this scam, where cybercriminals offer both support services and automated bots, allowing novice criminals to scam people en masse with ease. This method allows less-skilled scammers to create their own fully automated fake websites, fraudulent messages, and interactive chatbots with on-the-fly language translation, and more. 

Advanced fee scams – You’re eligible for benefits, but we just need a small fee!

Advanced fee scams involve fraudsters describing and promising a benefit – such as a scholarship, student loan forgiveness, or back-to-school vouchers – in exchange for an up-front payment. However, there is in fact no benefit, and the fraudsters usually disappear after the “fee” is paid.

Student tax scam – A student tax is owed; pay or face consequences!

Students (or their parents) who are heading off to college may encounter fraudulent messages in which scammers pretending to be from the government claim that there is a student tax that requires payment. However, the claimed tax does not exist; it’s an attempt at fraud, and, following any successful collection, the scammers disappear.

How to stay safe

Students and parents should be aware that the back-to-school season is an attractive time for scammers. Stay vigilant; read messages similar to the examples shared above carefully, and check the sender’s email address, the content of the message, any attached links, and so on. Don’t make hasty decisions.

Because scams are becoming more sophisticated and smartphone users are more susceptible, students and parents shouldn’t rely solely on their ability to spot a scam attempt. Having reliable smartphone protection based on a prevention-first approach is essential.  

ESET Mobile Security for Android can defend users against a wide spectrum of mobile threats, including malware, phishing links, and physical theft. See what’s inside:

Android antivirus with 24/7 scanning – Users are protected against malicious app installs and other malware. The antivirus can also check all files and device folders available via USB on the Go connections.

Anti-Phishing – Protects against malicious websites attempting to acquire your sensitive information – usernames, passwords, banking information, or credit card details on most popular Android browsers. Also, ESET Link Scanner can recognize phishing links coming from apps such as in-game messages.

Payment Protection – This feature adds an extra layer of security to apps like Google Pay or your mobile banking app. When active, Payment Protection prevents malicious apps from reading, modifying, or overlaying content on your protected apps – helping to stop phishing attempts and data leaks.

Anti-Theft – This feature logs all unauthorized attempts to unlock the phone or screen, and changes of a SIM card. The user is then notified via email. The Anti-Theft feature also tracks a missing device.

Try ESET Mobile Security, now at 50% off!

Prepare for school without worries

Preparations for going back to school can be stressful, and the last thing students or their parents want is to deal with extra problems related to being scammed. Purchase school supplies, browse the internet, and communicate online with peace of mind, with ESET Mobile Security.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET PROTECT Elite is a Security Winner of the 2025 CRN Tech Innovators

SAN DIEGO, Calif.August 7, 2025ESET, a global leader in cybersecurity, announced today that CRN®, a brand of The Channel Company, has named ESET PROTECT Elite a winner in the 2025 CRN Tech Innovator Awards for the Endpoint Protection/Extended Detection and Response Security category. The annual CRN Tech Innovator Awards spotlight innovative technology vendors across 33 categories, including storage, networking, and security, that are driving progress across the IT channel.

“The CRN Tech Innovators Awards are well recognized in the industry, making this an important recognition for the ESET PROTECT portfolio of proactive, prevention-first business solutions,” said Ryan Grant, Country Manager, US and Canada. “With ESET PROTECT Elite, we’re helping our partners future-proof their portfolios with enterprise-grade XDR that addresses real-world customer challenges and delivers complete, multilayered protection. This award is a testament to our company’s continued focus on innovation and channel success.”

Designed for businesses of all sizes, ESET PROTECT Elite offers cutting-edge capabilities to solution providers in the IT channel. The platform includes the ESET’s award-winning, proprietary ransomware remediation solution. Unlike other solutions which rely on Volume Shadow Copy, ESET PROTECT Elite offers next-gen ransomware rollback enhanced with remediation features. Ransomware Remediation works in tandem with the ESET Ransomware Shield technology, enabling comprehensive rollback through automated file restoration from secure backups, limiting threat actor attempts to raise remediation costs. Together with other ESET LiveSense technology layers, this proactively blocks sophisticated attacks before they even happen, getting businesses ahead of future threats.

ESET AI Advisor is also included in ESET PROTECT Elite as an optional add-on module, which enables businesses to access SOC-level advisory, and enable enhanced security analyst workflows. Going beyond typical generative AI assistants that focus on soft features like administration or device management, ESET AI Advisor seamlessly integrates into the day-to-day operations of security analysts. This is a gamechanger for companies with limited IT resources that want to utilize the advantages of advanced XDR solutions.

“Each of the 2025 CRN Tech Innovators Awards winners is a standout offering that reimagines what’s possible in the IT channel,” said Jennifer Follett, VP, U.S. Content, and Executive Editor, CRN, The Channel Company. “Each creates the opportunity to build bold solutions that solve real-world challenges for end users and drive success for channel partners. We congratulate our winners for their commitment to innovation, partner success, and customer impact, and we can’t wait to see how they continue to push technology boundaries forward.”

The Tech Innovators Awards winners are featured in the August issue of CRN and can be viewed online at crn.com/techinnovators. A panel of CRN editors reviewed hundreds of cutting-edge vendor products and services, and solution provider testimonials, evaluating entries based on key capabilities, uniqueness, technical ingenuity, and the ability to meet customer and partner needs.

For more information on ESET’s award-winning PROTECT platform and business solutions, visit https://www.eset.com/us/business/small-and-medium/.

 

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×