See here: https://security.stackexchange.com/a/249484
> ... a newly discovered ransomware variant exhibits the ability to detect and compromise partitions (including hidden partitions), a behavior not thought to have been seen before in ransomware.
with a link to original source:
https://www.fortinet.com/blog/threat-research/newly-discover...
quote from that link:
> At the time of discovery, FortiGuard Labs researchers believed the ransomware was seeking out partitions to find possible hidden partitions setup by systems administrators to hide backup files. But further analysis confirmed an even more advanced technique. The DarkSide Ransomware variant seeks out partitions on a multi-boot system to find additional files to encrypt.