Researchers reported that attackers used PetrWrap, a customized ransomware strain built on Petya v3, in targeted intrusions against organizations. The malware spread laterally across compromised networks with PsExec, delayed execution to evade detection, and patched Petya at runtime to replace its original key-agreement process with the attackers’ own cryptographic implementation. It also modified the bootloader and ransom note to remove Petya branding while retaining Petya’s core disk-encryption behavior against NTFS MFT data using a Salsa20-based mechanism.
The report said the changes gave operators control over decryption, unlike earlier Petya variants that had implementation flaws, and concluded that recovery through cryptanalysis was not feasible because the malware used strong encryption correctly. Researchers linked the attacks to broader post-compromise activity commonly seen in targeted ransomware operations, including credential theft with tools such as Mimikatz, abuse of vulnerable or weakly protected servers, and exploitation of exposed RDP access to move from initial access to full network-wide encryption.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Securelist published technical analysis of PetrWrap, a ransomware family used in targeted attacks that spreads within compromised networks via PsExec and patches embedded Petya v3 at runtime. The report said the malware replaces Petya’s key-agreement mechanism with the attackers’ own cryptography, making decryption infeasible.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.