NotPetya, also known as Nyetya, ExPetr, PetrWrap, and sometimes GoldenEye or DiskCoderC in early reporting, is a destructive Windows malware outbreak from June 2017 that masqueraded as ransomware while functioning primarily as a wiper. It overwrites or corrupts critical boot structures, encrypts files in place, forces system reboot, and presents a ransom screen, but was not designed to provide reliable recovery to victims. The malware spread rapidly through trusted enterprise networks and caused global operational disruption, with especially severe impact in Ukraine before propagating internationally.
NotPetya combines destructive disk tampering with worm-like lateral movement. It steals credentials using a password-dumping component, uses named-pipe inter-process communication, and propagates across local networks through multiple mechanisms including PsExec, WMIC, and SMB exploitation associated with EternalBlue and EternalRomance. It installs itself on remote systems via rundll32 when accessed through administrative tools, creates a scheduled task to reboot infected hosts, and includes logic to enumerate or react to security software processes. Analysis has also noted local kill-switch behavior intended to prevent reinfection on the same host.
Technically, NotPetya shares some implementation traits with Petya and GoldenEye in its handling of the Master Boot Record and boot-region overwrite logic, but it is generally assessed as a distinct and more sophisticated strain rather than a simple variant of those families. It also incorporates file-encryption behavior more reminiscent of other ransomware families while pairing that with robust reboot fallback logic and several propagation paths. Under some conditions tied to detected antivirus processes, it alters behavior by suppressing network activity or writing meaningless boot-area data instead of the usual ransom-display path.
The malware is widely associated with the Russian state and, at high confidence, with Sandworm Team, a GRU-linked threat actor. Public government attributions and criminal indictments have tied Sandworm to the 2017 NotPetya attack as part of a broader pattern of destructive operations. NotPetya is regarded as one of the most damaging cyberattacks on record, affecting multinational enterprises and critical infrastructure providers well beyond its initial target set.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
現在、ウクライナを中心に「GoldenEye」「Petya」「PEtrwrap」と呼ばれている新たなMBR破壊型かつワーム型ランサムウェアの脅威が拡大しています。
These documents use the CVE-2017-0199 Office RTF vulnerability to download and run the Petya installer, which then executes the SMB worm and spreads to new computers on the same network.
Dillon has crafted his modified exploits to take advantage of the following vulnerabilities: CVE-2017-0143 Type confusion between WriteAndX and Transaction requests EternalRomance EternalSynergy
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sandworm Team has developed malware for its operations, including malicious mobile applications and destructive malware such as NotPetya and Olympic Destroyer.
Much has been written about the recent ExPetr/NotPetya/Nyetya/Petya outbreak... To date, nobody has been able to find any significant code sharing between ExPetr/Petya and older malware.
In October 2020, DOJ indicted members of GRU Unit 74455 for numerous cyberattacks, including the 2017 NotPetya Malware attack.
However, the technique of autonomous spread was like the NotPetya malware, attributed to APT28.
The combination of both circulated in May 2016 and were merged with slight changes under the new name of GoldenEye in December 2016.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoors (including backdoored images), packers, C2 protocols, and the creation of infected removable media.
また、Wmicによる横展開については、以下のコマンドを利用してリモートからユーザー名とパスワードを使用して接続しRundll32を呼び出すことでDLLをロードさせます。
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
SMBv1の脆弱性による横展開については、EternalBlueまたはEternalRomance(いずれもMS17-010の更新プログラム適用で修正される)で脆弱性を突き、DoublePulsarを設置、DoublePulsarを介してlsass.exeにインメモリでDLLインジェクションを行います。
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
NotPetyaは動作中のプロセスを列挙し、列挙したプロセスのハッシュ値が特定のウイルス対策製品のプロセス名のハッシュ値と合致するかを確認します。
The indictment charges the defendants ... with a computer hacking conspiracy intended to deploy destructive malware and take other disruptive actions...
CISA defines ransomware as “an ever-evolving form of malware designed to encrypt files on a device, rendering any files and the systems that rely on them unusable. Malicious actors then demand ransom in exchange for decryption.” | Once launched, the malware may connect to a command-and-control server to enable the criminals to move laterally across networks and encrypt and/or exfiltrate the organization’s data.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A destructive malware operation cited as an example of large-scale unintended collateral damage from cyber operations.
Destructive wiper masquerading as ransomware, spread via a compromised Ukrainian tax software update and caused massive global damage.
Destructive malware incident referenced as part of the wave of major cyberattacks that elevated cybersecurity into a major business risk.
Destructive pseudo-ransomware/wiper referenced as a historical case in discussion of cyber conflict history.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.