NotPetya, also known as Nyetya, is a Windows MBR-overwriting worm-ransomware deployed in June 2017. Although it presented a ransom demand, its destructive boot-record overwrite and disk-impacting behavior made recovery impractical for many victims. It combined file encryption with boot-region modification, forced reboot mechanisms, credential dumping, and local-network propagation. NotPetya spread using harvested credentials and remote administration mechanisms including PsExec and WMI, and exploited SMB vulnerabilities associated with EternalBlue and EternalRomance. It also used a custom password-dumping component, named-pipe communication, antivirus-process checks, event-log deletion, and a local reinfection-prevention mechanism. The outbreak began through a compromised software supply chain in Ukraine and caused extensive collateral disruption internationally, including major impacts on logistics, pharmaceutical, and delivery organizations. NotPetya is widely attributed by governments and industry to Russia's GRU-associated Sandworm group (Military Unit 74455).
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Reports indicate that this ransomware is a modified version of NotPetya, and uses compromised credentials to spread laterally through the network.
The ransomware can also perform lateral movement by using two exploits that came with the ShadowBrokers dump in April, called ETERNALBLUE and ETERNALROMANCE. These tools exploit vulnerabilities in SMBv1 (CVE-2017-0144 and CVE-2017-0145).
These documents use the CVE-2017-0199 Office RTF vulnerability to download and run the Petya installer, which then executes the SMB worm and spreads to new computers on the same network.
Dillon has crafted his modified exploits to take advantage of the following vulnerabilities: CVE-2017-0143 Type confusion between WriteAndX and Transaction requests EternalRomance EternalSynergy
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Military Unit 74455, known publicly as Sandworm, or APT44, "has been associated with the 2017 NotPetya attack and ongoing destructive operations against Ukraine."
Much has been written about the recent ExPetr/NotPetya/Nyetya/Petya outbreak... To date, nobody has been able to find any significant code sharing between ExPetr/Petya and older malware.
In October 2020, DOJ indicted members of GRU Unit 74455 for numerous cyberattacks, including the 2017 NotPetya Malware attack.
However, the technique of autonomous spread was like the NotPetya malware, attributed to APT28.
The combination of both circulated in May 2016 and were merged with slight changes under the new name of GoldenEye in December 2016.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
If Petya finds valid credentials, it will use either PsExec or WMIC to infect other computers connected to the LAN... Lateral movements (remote WMI): "process call create \"C:\\Windows\\System32\\rundll32.exe \\\"C:\\Windows\\perfc.dat\\\" #1"
Commans lines: schtasks /Create /SC once /TN "" /TR "<system folder>\shutdown.exe /r /f" /ST <time>
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Commans lines: schtasks /Create /SC once /TN "" /TR "<system folder>\shutdown.exe /r /f" /ST <time>
Commans lines: schtasks /Create /SC once /TN "" /TR "<system folder>\shutdown.exe /r /f" /ST <time>
It also contains a lightweight version of Mimikatz. It is used to dump valid credentials from memory... After initial infection, the ransomware will drop a tool in the %temp% folder, of what seems to be a lightweight version of Mimikatz... The tools are used to steal valid credentials to spread to other hosts in the network.
If Petya finds valid credentials, it will use either PsExec or WMIC to infect other computers connected to the LAN.
Greenberg describes how NotPetya, a supply chain attack designed to destroy systems, spread beyond the conflict resulting in billions of dollars of collateral damage to companies like Maersk, Merck & FedEx.
The ransomware encrypts files on disk... It will also try to encrypt files on the disk/shares with the following file extensions...
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an example of a black-swan self-propagating ransomware event.
Destructive malware referenced as part of the 2017 NotPetya attack.
Destructive malware attack referenced as a prior Sandworm-associated operation in 2017.
Destructive malware associated in the content with Sandworm's 2017 attack activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.