NotPetya, also known as Nyetya, ExPetr, PetrWrap, and sometimes GoldenEye in early reporting, is a destructive Windows malware strain that masqueraded as ransomware but functioned primarily as a wiper. It emerged in June 2017 and is widely associated with Sandworm, a Russian GRU-linked threat actor. The malware was initially distributed through a compromise of Ukrainian accounting software in a supply-chain operation and then spread rapidly across trusted enterprise networks, causing massive collateral damage well beyond its apparent intended target set in Ukraine.
NotPetya combines disk sabotage, file encryption-like destruction, credential theft, and wormable lateral movement. It overwrites the master boot record and manipulates boot-region data to render systems unbootable while also encrypting files in place. Although it presents a ransom demand, it was not designed to support reliable victim recovery, which is why it is broadly assessed as destructive rather than financially motivated ransomware. The malware steals credentials from memory using an embedded password-dumping component and propagates laterally using legitimate administrative tools such as PsExec and WMIC, as well as SMB exploitation associated with EternalBlue and EternalRomance. It also uses scheduled reboot mechanisms and multiple fallback methods to force system restart and trigger its destructive boot-stage behavior.
The malware includes defense-evasion and environment-awareness features. It checks for specific antivirus processes and alters behavior depending on what it finds, including suppressing some network activity or changing how it corrupts boot data. It uses rundll32.exe for execution on remote systems, named-pipe communication with its credential-dumping component, and a local kill-switch style mechanism to avoid reinfection on already affected hosts.
NotPetya is one of the most consequential cyberattacks on record, causing billions of dollars in global losses across sectors including shipping, pharmaceuticals, logistics, and manufacturing. Its impact on multinational enterprises demonstrated how a regionally targeted supply-chain compromise could cascade through globally interconnected networks and software dependencies.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
現在、ウクライナを中心に「GoldenEye」「Petya」「PEtrwrap」と呼ばれている新たなMBR破壊型かつワーム型ランサムウェアの脅威が拡大しています。
These documents use the CVE-2017-0199 Office RTF vulnerability to download and run the Petya installer, which then executes the SMB worm and spreads to new computers on the same network.
Dillon has crafted his modified exploits to take advantage of the following vulnerabilities: CVE-2017-0143 Type confusion between WriteAndX and Transaction requests EternalRomance EternalSynergy
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sandworm Team has developed malware for its operations, including malicious mobile applications and destructive malware such as NotPetya and Olympic Destroyer.
Much has been written about the recent ExPetr/NotPetya/Nyetya/Petya outbreak... To date, nobody has been able to find any significant code sharing between ExPetr/Petya and older malware.
In October 2020, DOJ indicted members of GRU Unit 74455 for numerous cyberattacks, including the 2017 NotPetya Malware attack.
However, the technique of autonomous spread was like the NotPetya malware, attributed to APT28.
The combination of both circulated in May 2016 and were merged with slight changes under the new name of GoldenEye in December 2016.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoors (including backdoored images), packers, C2 protocols, and the creation of infected removable media.
また、Wmicによる横展開については、以下のコマンドを利用してリモートからユーザー名とパスワードを使用して接続しRundll32を呼び出すことでDLLをロードさせます。
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
SMBv1の脆弱性による横展開については、EternalBlueまたはEternalRomance(いずれもMS17-010の更新プログラム適用で修正される)で脆弱性を突き、DoublePulsarを設置、DoublePulsarを介してlsass.exeにインメモリでDLLインジェクションを行います。
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
NotPetyaは動作中のプロセスを列挙し、列挙したプロセスのハッシュ値が特定のウイルス対策製品のプロセス名のハッシュ値と合致するかを確認します。
Greenberg describes how NotPetya, a supply chain attack designed to destroy systems, spread beyond the conflict resulting in billions of dollars of collateral damage to companies like Maersk, Merck & FedEx.
CISA defines ransomware as “an ever-evolving form of malware designed to encrypt files on a device, rendering any files and the systems that rely on them unusable. Malicious actors then demand ransom in exchange for decryption.” | Once launched, the malware may connect to a command-and-control server to enable the criminals to move laterally across networks and encrypt and/or exfiltrate the organization’s data.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive malware delivered via a supply-chain attack, designed to destroy systems and causing major collateral damage beyond the intended conflict zone.
A destructive malware operation cited as an example of large-scale unintended collateral damage from cyber operations.
Destructive wiper masquerading as ransomware, spread via a compromised Ukrainian tax software update and caused massive global damage.
Destructive malware incident referenced as part of the wave of major cyberattacks that elevated cybersecurity into a major business risk.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.