NotPetya (also tracked as ExPetr/Petya.A) hit organizations as destructive malware masquerading as ransomware, encrypting or wiping systems after modifying the Windows Master Boot Record (MBR) and forcing a reboot that left victims unable to load Windows. Researchers observed the malware being launched via rundll32.exe, displaying a $300 Bitcoin ransom demand, and propagating laterally through Windows networks using SMB, WMIC, and the leaked NSA-linked exploits EternalBlue and EternalRomance against systems missing Microsoft’s MS17-010 patch for CVE-2017-0144.
Investigations tied the broader outbreak closely to Ukraine, where reporting pointed to a compromised MEDoc software update mechanism as the initial infection vector in a supply-chain attack. Later reporting said Ukrainian police arrested a 51-year-old man accused of distributing the malware through links shared on a blog and social media, allegedly causing about 400 infections. Separate research also noted low-confidence similarities between NotPetya and earlier BlackEnergy/TeleBots destructive operations, including overlapping file-extension targeting and shutdown behavior, reinforcing suspicions of a connection to prior Ukraine-focused attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
ESET published reporting that linked the activity to TeleBots and described supply-chain attacks against Ukraine. This represented an attribution-related development in understanding the campaign.
SANS analyzed DLL samples of the new Petya variant and observed execution via rundll32, MBR modification, a reboot into a fake CHKDSK sequence, and a ransom note demanding $300 in Bitcoin via a Posteo email address. The analysis also noted immediate port 445 traffic and ARP activity from infected hosts, supporting SMB-based propagation.
In June, Ukraine's Cyber Police said the broader outbreak's initial infection vector was the update mechanism of Ukrainian financial software provider MEDoc. Cisco, Kaspersky, and Microsoft were also cited as implicating MEDoc's compromised update system.
The EternalBlue exploit, later cited as a propagation mechanism for NotPetya/ExPetr, was released by the Shadow Brokers. The exploit targeted CVE-2017-0144.
BlackEnergy destructive malware, including KillDisk variants, was used in attacks in Ukraine and is widely associated with the 2015 Ukraine power grid attack. Later research compared NotPetya/ExPetr against these older samples.
Researchers later compared ExPetr/NotPetya with older BlackEnergy malware, finding similarities in targeted file extensions and some implementation patterns. They developed a YARA rule that matched only BlackEnergy and ExPetr samples in their collection, but stressed this was not definitive proof of a relationship.
Ukraine's Cyber Police arrested a 51-year-old man in Nikopol and charged him with distributing Petya.A/NotPetya. Authorities alleged he shared a video and links that led 400 victims to download the malware.
A new Petya variant was used in a widespread attack that heavily affected Ukraine and spread globally, damaging systems by overwriting the master boot record while posing as ransomware. Reports said it propagated over SMB using EternalBlue, with some also citing EternalRomance and WMIC-based movement.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securelist.com
Open sourcethreatpost.com
Open sourcewelivesecurity.com
Open sourceisc.sans.edu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.