Ukraine faced another wave of disruptive ransomware as researchers identified FakeCry, a WannaCry-lookalike campaign that primarily hit Ukrainian victims and appeared to overlap with infrastructure previously associated with M.E.Doc-linked outbreaks such as XData and NotPetya/Nyetya. The malware was not a true WannaCry clone: it used a separate dropper, required specific command-line arguments, relied on a Tor-based command-and-control server, and terminated processes before encrypting files in use, suggesting a more tailored operation than a commodity copycat attack.
A related regional campaign, Bad Rabbit, later struck organizations across Eastern Europe and Russia through compromised websites serving a fake Adobe Flash update, then spread internally using SMB, weak-credential brute forcing, mimikatz-like tooling, and the EternalRomance exploit associated with MS17-010. Cisco Talos reported that Bad Rabbit modified the Master Boot Record, used DiskCryptor-related components to encrypt disks and files, and shared a core codebase and similar build tooling with Nyetya, reinforcing concerns that multiple ransomware incidents in the region were closely connected in tradecraft even when presented as ordinary criminal extortion.

TTPs, infrastructure, and targeting history in one profile.
11 events from the most recent confirmed update back to the earliest known activity.
ESET reported that the October 24, 2017 campaign hit Kiev Metro, Odessa airport, Odessa naval port, and the Ukrainian ministries of infrastructure and finance, with additional victims reported in Russia and other countries. The company identified the malware as Diskcoder.D, a new Petya-family variant, and published preliminary details including Mimikatz use, hardcoded credentials, and IOCs tied to 1dnscontrol.com.
Talos reported that Bad Rabbit spread inside networks using SMB, weak credentials, mimikatz-like tooling, and the EternalRomance exploit, while requiring user interaction for initial infection. The researchers also assessed with high confidence that Bad Rabbit shared a core codebase and similar build tooling with Nyetya.
Talos assessed that the Bad Rabbit malware was active for approximately six hours before the 1dnscontrol[.]com distribution domain was taken down. This curtailed the initial drive-by delivery infrastructure used in the campaign.
Cisco Talos observed the Bad Rabbit ransomware campaign on October 24, 2017, with initial downloads seen around 08:22 UTC. The malware was distributed through compromised websites that redirected users to download a fake Adobe Flash Player installer.
The article states that the NotPetya outbreak began on Tuesday and places it after the start of the FakeCry campaign. It is also described as one of several Ukraine-focused ransomware operations tied by researchers to M.E.Doc update infrastructure.
According to MalwareHunter, the fourth ransomware campaign began on Monday, one day before the NotPetya outbreak. Most submitted samples appeared to come from Ukrainian victims, and the malware was designed to resemble WannaCry while differing substantially in code and behavior.
The references identify XData as an earlier ransomware campaign in Ukraine and place it in mid-May. The article later links it to the same broader cluster of Ukraine-focused ransomware activity.
BleepingComputer reported that a fourth ransomware campaign targeting Ukraine had been discovered, following XData, PSCrypt, and NotPetya. The report highlighted technical analysis from MalwareHunter and the apparent overlap with M.E.Doc-related infrastructure.
In response to the NotPetya-related allegations, M.E.Doc said it had not hosted trojanized versions of its applications. The company also said on Facebook that it had enlisted Cisco experts and invited Ukraine's Cyber Police to investigate its servers.
MalwareHunter identified a file path referencing M.E.Doc IS-pro software, suggesting the newly discovered ransomware may have been distributed through M.E.Doc-related infrastructure. The article notes uncertainty over whether this came from a trojanized update server or a compromised installation package.
PSCrypt is described as another Ukraine-focused ransomware campaign that occurred the week before NotPetya. It is cited as one of the earlier incidents preceding the newly discovered WannaCry-lookalike strain.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
securelist.com
Open sourceblog.talosintelligence.com
Open sourcewired.com
Open sourcewelivesecurity.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.