Janus is the threat actor name associated with the Petya ransomware family and its later Mischa and GoldenEye variants. The actor operated a ransomware-as-a-service program under the Janus name, allowing affiliates to distribute the malware in exchange for a tiered share of profits, reportedly reaching as high as 85% for top-performing distributors. The branding and naming of Petya, Mischa, GoldenEye, and Janus drew on references to the James Bond film GoldenEye. Janus became known for technically distinctive ransomware operations beginning in 2016. Petya differed from conventional file-encrypting ransomware by overwriting boot-related disk sectors and encrypting the Master File Table, rendering files inaccessible after a forced reboot while leaving file contents physically present on disk. Because Petya required elevated privileges to complete this attack chain, Janus paired it with Mischa, a fallback ransomware module that performed traditional file-by-file encryption when administrative access was unavailable. These capabilities were later combined and rebranded in GoldenEye. The actor relied heavily on socially engineered spam campaigns for initial access, especially phishing lures themed as job applications, job offers, and legal matters. Campaigns were noted for polished language, including fluent German in some operations, and for using malicious attachments or links to online storage services. The malware emphasized user execution rather than exploit kits or advanced exploitation. Janus-associated malware demonstrated substantial tradecraft in payload protection and execution. Reported characteristics include heavily obfuscated droppers, self-modifying code, privilege checks to determine whether to deploy Petya or Mischa, offline key generation without dependence on command-and-control infrastructure, and forced system reboot behavior to trigger Petya’s disk-encryption routine. Mischa also used reflective loading and process injection into legitimate Windows processes, and encrypted data across local, removable, and remote drives. GoldenEye and earlier Petya/Mischa campaigns were regarded as effective and profitable criminal ransomware operations. Available reporting also indicates that the original Janus author was likely not responsible for the later Ukraine-focused Petya-like destructive campaign commonly referred to as NotPetya; that later operation was assessed as using pirated and modified Petya code rather than being a direct Janus campaign. Janus has also been identified as the original author of Petya and as the operator behind the final GoldenEye-era releases.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Identified as the original author of the Petya ransomware project. The content states Janus was likely not involved in later Ukraine-focused outbreaks (e.g., NotPetya/EternalPetya) and that his Petya code was pirated/extended by another actor. Janus publicly released a private key/master key enabling decryption for victims of earlier Petya/GoldenEye infections, effectively shutting down the Petya project.
Threat actor behind the Petya and GoldenEye ransomware campaigns, using phishing emails themed as job applications and automated ransom payment via a TOR hidden service.
Operator/creator behind the Petya and Mischa double-ransomware offering, distributing it via spam email campaigns and running it as an affiliate-style ransomware-as-a-service program.
A ransomware-as-a-service affiliate program offering distribution of Petya installers that can also deploy Mischa when administrative privileges are unavailable. The service advertises revenue sharing, administration features, and use by malware distributors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.