The malware outbreak initially labeled Petya spread rapidly from Ukraine to multinational networks worldwide, disrupting banks, airports, government agencies, utilities, media outlets, and major companies including Maersk, Merck, DLA Piper, WPP, and Mondelez. Investigators tied the initial infection chain to the update mechanism of the Ukrainian accounting software M.E.Doc, after which the malware propagated aggressively using the Windows SMB flaw patched in MS17-010, the leaked NSA-linked exploits EternalBlue and EternalRomance, credential theft tools such as Mimikatz/LSADump, and lateral movement through PSExec and WMI. Unlike conventional file-encrypting ransomware, it overwrote the master boot record and encrypted core disk structures, crippling systems across internal networks.
Researchers and later government investigators concluded the operation was likely designed for destruction rather than profit, despite a $300 bitcoin demand, because its payment and recovery process was effectively broken and victims had little realistic chance of restoration. The attack became widely known as NotPetya, and its financial impact ran into the hundreds of millions of dollars for some victims, with Maersk alone reporting losses on that scale. In 2020, the US Justice Department charged six alleged officers of Russia's GRU Unit 74455 and linked the Sandworm group to NotPetya as part of a broader campaign of destructive cyber operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
18 events from the most recent confirmed update back to the earliest known activity.
On 2020-10-19, the U.S. Department of Justice unsealed charges against six Russian GRU Unit 74455 officers, alleging they were members of Sandworm and responsible for NotPetya among other destructive operations. The indictment formalized U.S. attribution of the 2017 outbreak to Russian state actors.
On 2018-02-15, the United Kingdom joined the United States in publicly attributing the 2017 NotPetya attack to the Russian military. UK Defence Secretary Gavin Williamson said Russia was undermining international norms and indicated the UK would respond, while Moscow denied the accusation.
On 2018-02-15, the Trump administration publicly blamed the Russian military for the June 2017 NotPetya attack and warned the operation would carry international consequences. The statement described NotPetya as a destructive campaign aimed at destabilizing Ukraine and highlighted its global financial impact.
On 2018-01-12, The Washington Post reported that the CIA had concluded the June 2017 NotPetya attack was carried out by Russian military hackers. The report said the operation was intended to disrupt Ukraine's financial system and had wiped data at Ukrainian banks, energy firms, government offices, and an airport.
By 2017-12-19, reporting highlighted researcher consensus that NotPetya was not designed to make money but instead to cause destruction while masquerading as ransomware. This marked a broader shift in public understanding of the incident from cybercrime to deliberate sabotage.
On 2017-08-17, Maersk said the NotPetya attack would cost the company hundreds of millions of dollars, illustrating the scale of business disruption caused by the malware. The disclosure became one of the clearest early measures of the outbreak's financial impact on a global enterprise.
By 2017-08-09, TNT Express was facing customer backlash over severe shipment delays and service disruption caused by the June NotPetya attack. The report highlighted TNT as another major victim still struggling with operational recovery weeks after the outbreak.
By 2017-07-25, reporting indicated Ukraine was bracing for additional cyberattacks after the June outbreak, reflecting ongoing concern that the incident was part of a broader campaign rather than a one-off ransomware event. The warning came amid continued recovery and investigation into the damage.
On 2017-07-05, Ukrainian officials, investigators, and Cisco Talos reported evidence that attackers had inserted a backdoor into MeDoc software updates, using a stolen employee password, altered configuration files, and tampered update infrastructure. The findings strengthened the view that NotPetya was a deliberate supply-chain attack that may have enabled broad network compromise before systems were destroyed.
On 2017-07-05, Ukraine's cybercrime unit said it seized the servers of accounting software firm MeDoc after detecting fresh activity, aiming to prevent any further malware spread linked to the NotPetya outbreak. The action reflected an official response focused on the suspected initial infection vector.
On 2017-07-05, Cisco Talos published technical analysis describing the 'MeDoc connection,' adding detail to claims that the Ukrainian software's update mechanism played a central role in the initial compromise chain. This helped solidify understanding of how the outbreak was seeded.
On 2017-07-03, Ukrainian CyberPolice said tax software firm M.E. Doc was under investigation and could face criminal charges over its alleged role in spreading NotPetya. Officials said the company had ignored repeated warnings about insecure IT infrastructure while investigators examined claims that a malicious software update seeded the outbreak.
On 2017-06-28, security researchers reported that creating a read-only file named 'perfc' in the C:\Windows folder could prevent NotPetya from infecting an individual machine. They emphasized this was not a universal kill switch and would not stop the malware's broader spread across networks.
On 2017-06-28, public concern escalated as officials warned about the attack's rapid spread and lack of a kill switch, and U.S. Congressman Ted Lieu urged the NSA to help mitigate the incident and disclose any relevant capabilities. Reporting emphasized that the malware was more destructive than WannaCry and could spread inside networks using stolen credentials.
On 2017-06-27, analysts reported that the malware used EternalBlue, EternalRomance, credential dumping tools such as Mimikatz/LSADump, and lateral movement via PSExec and WMI. Researchers also concluded the campaign was likely intended for destruction rather than profit because it encrypted core disk structures and used a broken ransom-payment workflow.
As the malware spread on 2017-06-27, major international victims including Maersk, Merck, DLA Piper, WPP, Mondelez, and Rosneft reported operational disruptions. The outbreak reached multiple countries beyond Ukraine, including Russia, Poland, Italy, Spain, France, India, and the United States.
On 2017-06-27, a destructive malware outbreak initially called Petya/PetyaWrap began spreading rapidly, with researchers and security firms pointing to the Ukrainian accounting software MeDoc update mechanism as the likely initial infection vector. Ukraine was hit especially hard, affecting government agencies, banks, airports, utilities, media, and Chernobyl monitoring systems.
In March 2017, Microsoft released bulletin MS17-010 to fix the Windows SMB vulnerability later exploited with EternalBlue during the NotPetya outbreak. Multiple reports note the malware also spread through credential theft and administrative tools, not only the SMB exploit.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
47 references tracked. Mallory keeps watching after this page renders.
secureworks.com
Open sourcezdnet.com
Open sourcezdnet.com
Open sourcecbsnews.com
Open sourceweb.archive.org
Open sourcekrebsonsecurity.com
Open sourcenpr.org
Open sourcecnet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.