Description Summary
NotPetya was a destructive June 2017 cyberattack that masqueraded as Petya ransomware but functioned as a wiper — its encryption was irreversible by design, with no viable recovery even after payment. Attributed by the U.S., U.K., and allied governments to Sandworm (Russia's GRU), it spread from a trojanized update of the Ukrainian M.E.Doc accounting software using the EternalBlue and EternalRomance exploits plus Mimikatz-harvested credentials and PsExec/WMI. It caused an estimated USD 10 billion in global damage, crippling Maersk, Merck, and FedEx/TNT.
Threat Actor
Sandworm (Russian GRU Unit 74455). State-sponsored destructive operation disguised as ransomware.
Technical Indicators
Encryption Extension
None consistent — overwrites the Master Boot Record (MBR); file-level encryption on some files
Encryption Algorithm
Salsa20/AES (cosmetic); keys discarded — effectively an unrecoverable wiper
Ransom Note Name
Fake 'Oops, your important files are encrypted' note demanding ~$300 in Bitcoin
Targeted Industries
Government, Shipping/Logistics, Pharmaceuticals, Critical infrastructure
First Seen
June 2017
Last Seen
June 2017 (single destructive campaign)
Geographical Location
Ukraine (origin); global spillover
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 1 | T1195.002 | Supply Chain Compromise (M.E.Doc update) |
| Lateral Movement x 3 | T1210 | Exploitation of Remote Services (EternalBlue/EternalRomance) |
| T1570 | Lateral Tool Transfer | |
| T1021.002 | SMB/Windows Admin Shares | |
| Credential Access x 1 | T1003.001 | OS Credential Dumping: LSASS (Mimikatz) |
| Execution x 1 | T1047 | Windows Management Instrumentation |
| Impact x 2 | T1561.002 | Disk Structure Wipe (MBR) |
| T1486 | Data Encrypted for Impact |