NotPetya, also known as Nyetya and ExPetr, is destructive Windows malware with worm-like propagation that emerged on June 27, 2017. Although it presents ransom demands, it functions as a wiper: its encryption design does not provide a reliable mechanism for recovering victims’ data through payment. The attack is attributed to Sandworm, a Russian military intelligence threat group associated with the GRU. Initially targeting Ukrainian organizations, it spread internationally and caused billions of dollars in damage across shipping, logistics, energy, manufacturing, finance, and healthcare.
The initial campaign used a software supply-chain compromise of M.E.Doc, a Ukrainian accounting application, to distribute malicious updates. After execution, NotPetya uses a modified Mimikatz implementation to steal Windows credentials and propagate through PsExec and Windows Management Instrumentation. It also scans network hosts and exploits vulnerable SMBv1 services using EternalBlue and EternalRomance. Credential-based propagation allows it to reach systems even when the exploited SMB vulnerabilities have been patched. It disguises its dropped PsExec utility through renaming.
NotPetya encrypts files matching a hard-coded extension list using a dynamically generated 128-bit AES key. With administrator privileges, it modifies the master boot record to enable encryption of disk structures, including the master file table, and reboots the computer, rendering it unusable. The victim identifier displayed for ransom payment has no demonstrated relationship to the file-encryption key, making attacker-assisted restoration unlikely. Its combination of credential theft, automated lateral movement, and destructive encryption produces widespread data loss and operational disruption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The manual contains an MS17-010 section discussing vulnerable Windows systems. The report also states that WannaCry, Petya, and NotPetya leveraged EternalBlue.
NotPetya's lateral movement techniques include “EternalRomance - another Windows SMBv1 exploit.” The alert explicitly lists CVE-2017-0145 among the vulnerabilities placing unpatched Windows systems at risk.
These documents use the CVE-2017-0199 Office RTF vulnerability to download and run the Petya installer, which then executes the SMB worm and spreads to new computers on the same network.
Dillon has crafted his modified exploits to take advantage of the following vulnerabilities: CVE-2017-0143 Type confusion between WriteAndX and Transaction requests EternalRomance EternalSynergy
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sandworm Team has distributed NotPetya by compromising the legitimate Ukrainian accounting software M.E.Doc and replacing a legitimate software update with a malicious one.
The NotPetya attack of 2017, attributed to the GRU’s Sandworm unit, exemplifies this. Using the EternalBlue exploit, the attack was ostensibly targeted at Ukraine but spread globally, causing over $10 billion in damages.
Much has been written about the recent ExPetr/NotPetya/Nyetya/Petya outbreak... To date, nobody has been able to find any significant code sharing between ExPetr/Petya and older malware.
In October 2020, DOJ indicted members of GRU Unit 74455 for numerous cyberattacks, including the 2017 NotPetya Malware attack.
However, the technique of autonomous spread was like the NotPetya malware, attributed to APT28.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
If Petya finds valid credentials, it will use either PsExec or WMIC to infect other computers connected to the LAN... Lateral movements (remote WMI): "process call create \"C:\\Windows\\System32\\rundll32.exe \\\"C:\\Windows\\perfc.dat\\\" #1"
It also contains a lightweight version of Mimikatz. It is used to dump valid credentials from memory... After initial infection, the ransomware will drop a tool in the %temp% folder, of what seems to be a lightweight version of Mimikatz... The tools are used to steal valid credentials to spread to other hosts in the network.
After establishing a cryptographic context, the process recursively browses the file system, looks for files with specific extensions, and encrypts them.
If Petya finds valid credentials, it will use either PsExec or WMIC to infect other computers connected to the LAN.
EternalBlue required zero user interaction and zero authentication, allowing it to spread laterally across networks at machine speed. The article also recommends restricting internal SMB traffic to limit the blast radius of lateral movement.
MS08-067 allowed an unauthenticated attacker to send a specially crafted RPC request over SMB and obtain SYSTEM-level privileges. EternalBlue targeted SMBv1 transaction handling and spread laterally across networks without authentication or user interaction.
A sudden spike in SMB2_CREATE requests followed by rapid SMB2_READ operations across hundreds of distinct file extensions may indicate ransomware actively encrypting a file share.
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a historical comparison: the 2017 attack disrupted Maersk’s shore and terminal systems without preventing its vessels from maneuvering. The article does not link NotPetya to the current tanker intrusion.
Described as a wiper, rather than ransomware, that affected Maersk’s booking, EDI, and terminal operations worldwide in 2017.
Presented as a historical example of maritime cyber risk. It spread through Maersk’s IT systems, disrupted container-terminal operations worldwide, and caused reported losses of $250–$300 million. The content does not connect it to the 2026 tanker incidents.
Ransomware campaign described as weaponizing EternalBlue to spread through vulnerable SMBv1 services, with severe impacts on global infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.