Petya is a Windows ransomware family first observed in 2016 that distinguishes itself by compromising the boot process rather than only encrypting user files. It overwrites the master boot record and, after a forced reboot, runs a malicious bootloader that displays a fake disk-check screen before encrypting the NTFS master file table, rendering the operating system unbootable and files inaccessible. Petya supports both MBR- and GPT-partitioned disks and uses strong cryptographic components including Salsa20 and elliptic-curve cryptography in its decryption workflow.
Petya was notably distributed through German-language job-application themed spam and phishing campaigns aimed at HR personnel in German-speaking countries. The lure typically relied on the victim executing a disguised attachment and approving a UAC prompt, because Petya required administrative privileges to perform its disk-level modifications. After execution, the malware unpacked an in-memory installer component, modified boot structures, triggered a system crash or reboot, and completed encryption during the next startup before presenting its skull-themed ransom screen and Tor-based payment instructions.
The family later evolved operationally through companion and successor strains. Mischa was introduced as a fallback payload for cases where administrative privileges were not obtained, using conventional file encryption instead of disk-level sabotage. GoldenEye later combined Petya- and Mischa-style functionality in a refined campaign that continued to use job-application lures. Petya has also been reused or imitated by later threats, including PetrWrap, which embedded and patched Petya code for targeted enterprise ransomware operations, and the 2017 NotPetya outbreak, which borrowed Petya-like boot and MFT disruption techniques but is widely regarded as a distinct and more destructive malware strain rather than a true Petya variant.
Petya is associated with operators using the name Janus and became one of the most prominent examples of disk-encrypting ransomware because of its low-level manipulation of boot records and filesystem metadata rather than straightforward per-file encryption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These tools include the EternalBlue exploit (which was previously used by WannaCry and Petya).
These documents use the CVE-2017-0199 Office RTF vulnerability to download and run the Petya installer, which then executes the SMB worm and spreads to new computers on the same network. | The main culprit behind this attack is a new version of Petya, a ransomware that encrypts MFT (Master File Tree) tables for NTFS partitions and overwrites the MBR (Master Boot Record) with a custom bootloader that shows a ransom note and prevents victims from booting their computer. Later, it was discovered this is a new strain altogether, which researchers have started referring to as NotPetya or Petna.
6.CVE-2017-0144, CVE-2017-0145, CVE-2017-0143 Description: Windows SMBv1 Remote Code Execution Vulnerability WannaCry, Petya
6.CVE-2017-0144, CVE-2017-0145, CVE-2017-0143 Description: Windows SMBv1 Remote Code Execution Vulnerability WannaCry, Petya
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
hackers used a self-developed modification of Petya ransomware named PetrWrap.
This is a follow-up from our previous diary about today's ransomware attacks using the new Petya variant... Petya is a ransomware family that works by modifying the infected Windows system's Master Boot Record (MBR).
While the world is holding its breath, wondering where notorious cybercriminal groups like Lazarus or Telebots will strike next with another destructive malware such as WannaCryptor or Petya...
When Petya spread for the first time in March 2016... After a reboot the Master File Tabel (MFT) is encrypted... The evident similarity to Petya caused many researchers to name the new threat "Petya", too. But first doubts emerged soon, which are reflected in names like NotPetya, Nyetya, or Petna.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
So far, all theories regarding the spread of ExPetr/Petya point into two directions: Distribution via trojanized updates to MeDoc users Distribution via waterhole attacks in Ukrainian news websites (one case known)
感染の方法については、サードパーティ製のアプリケーション「MeDoc」経由や、メールに添付されたファイル経由で感染する等、色々な情報が流れていますが、今のところ弊社では確証のある情報は確認できていません。
また、Wmicによる横展開については、以下のコマンドを利用してリモートからユーザー名とパスワードを使用して接続しRundll32を呼び出すことでDLLをロードさせます。
加えて、このDLLには有効でないMicrosoftのデジタル署名が付加されています。この点についてもデジタル署名が付与されているだけ(有効かどうかを確認しない)で安全とみなす製品、人の目を逃れるためと考えられます。
After decrypting the payloads, an environment check is performed in order to choose which one of them will be installed. The process token... is used for choosing which installation path to follow next. Dropper comes with a list of Anti-Malware products, which presence is checked before the payload is deployed.
it scans the drive to see if it is a multi-boot system to find additional volumes/partitions to try and encrypt their files as well.
After decrypting the payloads, an environment check is performed in order to choose which one of them will be installed. The process token... is used for choosing which installation path to follow next. Dropper comes with a list of Anti-Malware products, which presence is checked before the payload is deployed.
なお、今回のマルウェアは、MBRの書き換えに加え、一般的なランサムウェアと同じくファイルの暗号化を行いますが、その際はファイルの拡張子は追加せず、元ファイルを暗号化データで上書きすることで暗号化処理を行います。
NotPetya NtRaiseHardError、InitiateSystemshutdownExW、ExitWindowsExの順で試行 shutdownコマンドのタスクスケジュールの生成
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
76 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Bootkit-style ransomware that encrypts critical NTFS MFT structures and replaces the boot process with malicious low-level code.
Ransomware referenced for its similar behavior of manipulating the boot process.
Ransomware that encrypts systems and overwrites the Master Boot Record, rendering machines unusable and hindering recovery.
Referenced as an example of a bootkit requiring low-level execution knowledge for analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.