NotPetya, also known as Nyetya, is a destructive Windows ransomware operation that emerged in June 2017. Although it presented ransom demands, its disk and file-encryption design made recovery impracticable in many cases and is widely assessed as destructive rather than financially motivated ransomware. It overwrites the Master Boot Record, deploys a custom bootloader, encrypts the NTFS Master File Table and targeted files, and forces a reboot to display a fake disk-check sequence and ransom screen. File encryption uses AES-128-CBC with a per-process session key protected using RSA-1024.
NotPetya was distributed through a compromised Ukrainian accounting-software update mechanism and initially concentrated on Ukrainian organizations before propagating internationally. It spread laterally within Windows networks using stolen credentials, PsExec, WMI, and SMB exploitation techniques including EternalBlue and EternalRomance, enabling severe collateral disruption at multinational organizations. The malware used password dumping, network enumeration, named-pipe communications, scheduled reboot tasks, event-log deletion, and security-product-aware execution logic. It is associated with Sandworm, also tracked as APT44, a Russian GRU-linked threat actor. The campaign caused extensive disruption to shipping, pharmaceutical, logistics, and other enterprise operations globally.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Reports indicate that this ransomware is a modified version of NotPetya, and uses compromised credentials to spread laterally through the network.
The ransomware can also perform lateral movement by using two exploits that came with the ShadowBrokers dump in April, called ETERNALBLUE and ETERNALROMANCE. These tools exploit vulnerabilities in SMBv1 (CVE-2017-0144 and CVE-2017-0145).
These documents use the CVE-2017-0199 Office RTF vulnerability to download and run the Petya installer, which then executes the SMB worm and spreads to new computers on the same network.
Dillon has crafted his modified exploits to take advantage of the following vulnerabilities: CVE-2017-0143 Type confusion between WriteAndX and Transaction requests EternalRomance EternalSynergy
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
NotPetya, deployed by Russia’s Sandworm (APT44) in 2017 through compromised Ukrainian accounting software, spread globally and caused an estimated $10 billion in damage.
Much has been written about the recent ExPetr/NotPetya/Nyetya/Petya outbreak... To date, nobody has been able to find any significant code sharing between ExPetr/Petya and older malware.
In October 2020, DOJ indicted members of GRU Unit 74455 for numerous cyberattacks, including the 2017 NotPetya Malware attack.
However, the technique of autonomous spread was like the NotPetya malware, attributed to APT28.
The combination of both circulated in May 2016 and were merged with slight changes under the new name of GoldenEye in December 2016.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The only confirmed initial infections comes through a malicious software update for a Ukrainian tax accounting software called MeDoc.
If Petya finds valid credentials, it will use either PsExec or WMIC to infect other computers connected to the LAN... Lateral movements (remote WMI): "process call create \"C:\\Windows\\System32\\rundll32.exe \\\"C:\\Windows\\perfc.dat\\\" #1"
Commans lines: schtasks /Create /SC once /TN "" /TR "<system folder>\shutdown.exe /r /f" /ST <time>
It also contains a lightweight version of Mimikatz. It is used to dump valid credentials from memory... After initial infection, the ransomware will drop a tool in the %temp% folder, of what seems to be a lightweight version of Mimikatz... The tools are used to steal valid credentials to spread to other hosts in the network.
If Petya finds valid credentials, it will use either PsExec or WMIC to infect other computers connected to the LAN.
Greenberg describes how NotPetya, a supply chain attack designed to destroy systems, spread beyond the conflict resulting in billions of dollars of collateral damage to companies like Maersk, Merck & FedEx.
After sharing the decryption keys with the C2, the ransomware will drop a ransom note and (usually very visibly) notify the infected user of its actions and ways to obtain the decryption key. | The ransomware recursively browses the file system, looks for files with specific extensions, and encrypts them. NOTPETYA performs file encryption using file-backed mappings to overwrite files of specifically targeted extensions.
One visible Telegram post referred to Pakistan Metrological Department access credentials, while another discussed .gov.bd infrastructure and DDoS activity.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a historical example of MBR-based bootloader behavior, including a fake CHKDSK display and MFT encryption.
Destructive malware deployed through compromised Ukrainian accounting software that spread globally and caused an estimated $10 billion in damage.
Mentioned only as an example of a black-swan self-propagating ransomware event.
Destructive malware referenced as part of the 2017 NotPetya attack.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.