The malware outbreak widely referred to as Petya, NotPetya, or GoldenEye began with a malicious update delivered through the Ukrainian accounting software MeDoc, then rapidly propagated inside victim networks using worm-like techniques. Microsoft reported that the malware combined ransomware behavior with lateral movement through stolen credentials, WMI, PsExec, and SMB-based exploitation, including ETERNALBLUE and ETERNALROMANCE tied to CVE-2017-0144 and CVE-2017-0145.
Once executed, the malware encrypted files, could overwrite the Master Boot Record (MBR), and erased Windows Event Logs, amplifying operational disruption across affected organizations. Advisory reporting said there was no practical decryption path because the email account used for ransom communications was shut down, while defenders were urged to segment SMB access, disable SMBv1 and WMIC where possible, apply Microsoft patches, maintain reliable backups, and ensure endpoint protection was updated.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
The advisory states that no decryption solution was available and that the email account used for ransom communications had been closed by the provider. As a result, paying the listed bitcoin ransom would not yield decryption tools or keys.
Over the prior 24 hours on 27 June 2017, the ransomware spread globally and propagated laterally using stolen credentials, WMI, PsExec, and the SMBv1 exploits ETERNALBLUE and ETERNALROMANCE. The malware also encrypted files, could overwrite the master boot record, and erased Windows Event Logs.
The only confirmed initial infection vector described was a malicious software update delivered through the Ukrainian tax accounting software MeDoc. This compromise seeded the ransomware outbreak that then spread inside victim networks.
Microsoft had already released patches in March 2017 for the SMBv1 vulnerabilities CVE-2017-0144 and CVE-2017-0145, which the malware later exploited via ETERNALBLUE and ETERNALROMANCE for lateral movement.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.