Petya is a boot-level ransomware family first seen in 2016 that overwrites the Master Boot Record (MBR) and encrypts the NTFS Master File Table (MFT), preventing the operating system from accessing files and rendering infected Windows systems unusable. Unlike conventional file-encrypting ransomware, Petya primarily locks the entire disk by manipulating the boot process; some reporting also notes that it presents a fake CHKDSK screen while encryption occurs and then displays a ransom note at boot.
The content also discusses the 2017 outbreak widely referred to as Petya, Petrwrap, ExPetr, or NotPetya, which reused Petya bootloader code but differed substantially from the original family. That 2017 strain spread like a worm, using SMB exploitation including EternalBlue and EternalRomance as well as credential-based lateral movement via WMIC and harvested credentials, with reporting linking major initial infections to the Ukrainian M.E.Doc accounting software update mechanism. Multiple sources in the content state that this 2017 variant was likely a destructive wiper masquerading as ransomware rather than a financially motivated extortion tool, with no reliable recovery path even if victims paid.
Petya and Petya-derived outbreaks heavily affected organizations in Ukraine and then spread internationally, impacting government networks, banks, transportation, energy, industrial enterprises, and major multinational companies including Maersk, Merck, Rosneft, WPP, and others. Reported Ukrainian victims included Kyivenergo, Ukrtelecom, Oschadbank, Sberbank, Ukrsotsbank, Ukrgasbank, OTP Bank, PrivatBank, Nova Poshta, Boryspil airport, Kyiv Metro, and Chernobyl radiation-monitoring systems. Some reporting cited in the content attributes the 2017 destructive campaign to a state actor, with later references linking NotPetya specifically to Russian military-linked operators.
Additional context in the content notes that Petya was also distributed through criminal channels, including a ransomware-as-a-service affiliate program called Janus. In that model, Petya installers could deploy the secondary ransomware Mischa when administrative privileges were unavailable. The content further notes that older Petya samples continued to circulate on platforms such as Discord’s CDN.
High-confidence behavioral details directly mentioned in the content include overwriting the MBR, encrypting the MFT, locking systems at boot, ransom demands including $300 in bitcoin in the 2017 outbreak, and use of a single payment email account that was later blocked. The content also mentions a host-level mitigation reported during the 2017 outbreak: creating a read-only file named perfc in C:\Windows to protect an individual machine from that specific campaign variant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
One key difference from WannaCry is that Petya does not simply encrypt disk files but rather locks the entire disk so nothing can be executed. It does it by encrypting the filesystem’s master file table so the operating system cannot retrieve files. | Lieu seeks to hold the NSA accountable for its leaked exploit, known as EternalBlue, which appears to have facilitated the malware’s spread. Last month, the ransomware known as WannaCry also leveraged EternalBlue in order to spread between networked machines that have not been updated to protect them from the vulnerability, which Microsoft issued a patch for back in March (MS17-010).
6.CVE-2017-0144, CVE-2017-0145, CVE-2017-0143 Description: Windows SMBv1 Remote Code Execution Vulnerability WannaCry, Petya
6.CVE-2017-0144, CVE-2017-0145, CVE-2017-0143 Description: Windows SMBv1 Remote Code Execution Vulnerability WannaCry, Petya
...disruptions ... attributed to a variant of the Petya ransomware, which we are calling “EternalPetya”. The malware was initially distributed through a compromised software update system and then self-propagated through stolen credentials and SMB exploits, including the EternalBlue exploit...
22 distinct techniques documented for this family, organized by ATT&CK tactic.
It seems to also be finding passwords on each infected computer and using those to spread as well.
ExPetr/PetrWrap/Petya was also distributed through a waterhole attack on https://t.co/j9DvYcEgW7
Analysts from Microsoft and the Slovakian-based cybersecurity company ESET both said the attack targeted M.E.Doc, a Ukrainian tax-accounting software company, before the ransomware quickly spread to at least 64 other countries.
However, much of the propagation is believed to have occurred by the malware’s use of WMI commands, MimiKatz, and PSExec.
// -- Scheduled task $cmd06 = "schtasks " nocase ascii wide $cmd07 = "/Create /SC " nocase ascii wide $cmd08 = " /TN " nocase ascii wide $cmd09 = "at %02d:%02d %ws" nocase ascii wide
It seems to also be finding passwords on each infected computer and using those to spread as well.
$cmd01 = "wevtutil cl Setup" ... $cmd04 = "wevtutil cl Application"
// COMMANDS // -- Clearing event logs & USNJrnl $cmd01 = "wevtutil cl Setup" ... $cmd05 = "fsutil usn deletejournal" ascii wide nocase
It seems to also be finding passwords on each infected computer and using those to spread as well.
Ms Carhart said the malware abused remote Windows administration tools to spread quickly across internal company computer networks.
the timing correlates to lateral movement via PSExec we observed in victim networks starting around 10:12 UTC. | Our analysis of the artifacts and network traffic at victim networks indicate that modified versions of the EternalBlue and EternalRomance SMB exploits were used, at least in part, to spread laterally.
Lieu seeks to hold the NSA accountable for its leaked exploit, known as EternalBlue, which appears to have facilitated the malware’s spread. Last month, the ransomware known as WannaCry also leveraged EternalBlue in order to spread between networked machines that have not been updated to protect them from the vulnerability, which Microsoft issued a patch for back in March (MS17-010).
Experts point to "aggressive" features of the malware that make it impossible to retrieve key files... security firm Comae described the variant as a "wiper" rather than straight-forward ransomware.
Impact: Begins encrypting files before the operating system loads, making recovery extremely difficult.
The “unprecedented” June 27 attack started in Ukraine -- hitting government computer networks and websites of banks, major industrial enterprises, the postal service, Kyiv's international airport, and its subway system -- before spreading to other countries and international companies around the world.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
48 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Bootkit-style ransomware that encrypts critical NTFS MFT structures and replaces the boot process with malicious low-level code.
Ransomware referenced for its similar behavior of manipulating the boot process.
Ransomware that encrypts systems and overwrites the Master Boot Record, rendering machines unusable and hindering recovery.
Referenced as an example of a bootkit requiring low-level execution knowledge for analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.