NotPetya (Petya) Ransomware

Description Summary

NotPetya was a destructive June 2017 cyberattack that masqueraded as Petya ransomware but functioned as a wiper — its encryption was irreversible by design, with no viable recovery even after payment. Attributed by the U.S., U.K., and allied governments to Sandworm (Russia's GRU), it spread from a trojanized update of the Ukrainian M.E.Doc accounting software using the EternalBlue and EternalRomance exploits plus Mimikatz-harvested credentials and PsExec/WMI. It caused an estimated USD 10 billion in global damage, crippling Maersk, Merck, and FedEx/TNT.

Threat Actor

Sandworm (Russian GRU Unit 74455). State-sponsored destructive operation disguised as ransomware.

Technical Indicators

Encryption Extension
None consistent — overwrites the Master Boot Record (MBR); file-level encryption on some files
Encryption Algorithm
Salsa20/AES (cosmetic); keys discarded — effectively an unrecoverable wiper
Ransom Note Name
Fake 'Oops, your important files are encrypted' note demanding ~$300 in Bitcoin
Targeted Industries
Government, Shipping/Logistics, Pharmaceuticals, Critical infrastructure
First Seen
June 2017
Last Seen
June 2017 (single destructive campaign)
Geographical Location
Ukraine (origin); global spillover

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 1 T1195.002 Supply Chain Compromise (M.E.Doc update)
Lateral Movement x 3 T1210 Exploitation of Remote Services (EternalBlue/EternalRomance)
T1570 Lateral Tool Transfer
T1021.002 SMB/Windows Admin Shares
Credential Access x 1 T1003.001 OS Credential Dumping: LSASS (Mimikatz)
Execution x 1 T1047 Windows Management Instrumentation
Impact x 2 T1561.002 Disk Structure Wipe (MBR)
T1486 Data Encrypted for Impact