Moonraker Petya is a worm that ESET reported GreyEnergy deployed in December 2016, prior to the June 2017 NotPetya attacks. ESET assessed it as a predecessor to NotPetya and described it as a more advanced Petya variant used in a separate GreyEnergy campaign. The malware was associated with GreyEnergy, a BlackEnergy successor subgroup linked to targeting critical infrastructure organizations in Central and Eastern Europe, especially Ukraine, with victims in sectors including energy and transportation. According to the provided content, Moonraker Petya had limited propagation via PsExec and included destructive and crypto functionality. The content does not provide additional high-confidence technical details or indicators of compromise specific to Moonraker Petya.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In December 2016 the attackers deployed a worm that we believe to have been a predecessor to NotPetya... hence we named this worm Moonraker Petya.
In December 2016 the attackers deployed a worm that we believe to have been a predecessor to NotPetya... hence we named this worm Moonraker Petya.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A more advanced version of Petya that ESET says GreyEnergy deployed in December 2016 in a separate campaign prior to NotPetya.
Pre-NotPetya worm deployed in Dec 2016 as a DLL (msvcrt120b.dll; internal name moonraker.dll). Spreads laterally using embedded/dropped PsExec, can render systems unbootable by wiping the first sector and modifying ACPI service ImagePath registry values, and includes file encryption with AES-256 plus a ransom note mimicking 'Green Petya' (RSA-2048-encrypted personal key and same onion addresses/text). Does not include Mimikatz credential harvesting or the EternalBlue exploit per the report.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.