A global ransomware outbreak linked to the NotPetya malware family—also tracked as Petrwrap, GoldenEye, and Nyetya—encrypted files, altered the Master Boot Record (MBR), and demanded a $300 Bitcoin payment from victims. The malware affected Microsoft Windows systems and was notable for rapidly moving through already-compromised environments rather than broadly scanning the internet for new targets.
Advisories said NotPetya propagated laterally inside networks using the EternalBlue SMB exploit addressed by Microsoft's MS17-010 bulletin, along with legitimate administration tools such as PsExec and WMI. Defenders were urged to apply the MS17-010 security update, restrict or block SMB where feasible, update endpoint protections, isolate infected hosts, and avoid paying the ransom because recovery was not assured.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On June 27, 2017, multiple organizations worldwide reported disruptions caused by a ransomware outbreak attributed to a new Petya variant. The malware was referred to by names including NotPetya, Petrwrap, GoldenEye, and Nyetya.
Following the June 27, 2017 outbreak, Malaysia's National Cyber Coordination and Command Centre said it was closely monitoring for signs of infection or propagation in Malaysia. The advisory also urged organizations to patch systems, restrict SMB exposure, isolate infected hosts, and avoid paying the ransom.
Microsoft issued security bulletin MS17-010 for Windows SMB vulnerabilities later associated with EternalBlue-based malware propagation. The NACSA advisory specifically recommends applying MS17-010 as a mitigation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.