NotPetya

MITRE ATT&CK: S0368 View on attack.mitre.org

Aliases: ExPetr, Diskcoder.C, GoldenEye, Petrwrap, Nyetya, BadRabbit, NonPetya, NotPetya, Petna, Pnyetya, nPetya

First seen
2017-06-27 00:00:00
Malware type
wiper, worm, ransomware
Family
Malware family
Operating systems
windows
Last IoC activity
2026-07-20 13:15:03
Profile updated
2026-07-07 12:44:42

Targeted industries: government-and-public-sector financial-services energy-and-utilities transportation-and-logistics healthcare-and-pharmaceutical manufacturing

Targeted regions: country_code:ua country_code:ru country_code:us country_code:gb country_code:fr country_code:de

Context

NotPetya is malware that was used by Sandworm Team in a worldwide attack starting on June 27, 2017. While NotPetya appears as a form of ransomware, its main purpose was to destroy data and disk structures on compromised systems; the attackers never intended to make the encrypted data recoverable. As such, NotPetya may be more appropriately thought of as a form of wiper malware. NotPetya contains worm-like features to spread itself across a computer network using the SMBv1 exploits EternalBlue and EternalRomance.

Detection coverage

  • 4 YARA rules
  • 356 Sigma rules

Malware & tools used

  • Service Execution (attack-pattern)
  • Scheduled Task (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Clear Windows Event Logs (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Exploitation of Remote Services (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • LSASS Memory (attack-pattern)
  • System Shutdown/Reboot (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Masquerading (attack-pattern)
  • Rundll32 (attack-pattern)
  • Local Accounts (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • Exploitation of Remote Services (attack-pattern)
  • Loss of Productivity and Revenue (attack-pattern)

Used by threat actors

Detection rules

  • CAPE_Badrabbit (yara-rule)
  • CAPE_Petrwrap (yara-rule)
  • MALPEDIA_Win_Petrwrap_Auto (yara-rule)
  • SEKOIA_Apt_Sandworm_Notpetya_Strings (yara-rule)

Related threat objects

Reports & references

  • MITRE ATT&CK — G0034 (report)
  • ESET — Telebots Back Supply Chain Attacks Against Ukraine (report)
  • ESET — New Ransomware Attack Hits Ukraine (report)
  • ESET — Bad Rabbit Not Petya Back (report)
  • services.google.com — Apt44 Unearthing Sandworm (report)
  • CISA — Aa22 110A (report)
  • Kaspersky — 91897 (report)
  • Kaspersky — 97937 (report)
  • Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
  • gov.uk — Uk Exposes Series Of Russian Cyber Attacks Against Olympic And Paralympic Games (report)
  • justice.gov — Download (report)
  • secureworks.com — Iron Viking (report)
  • Cisco Talos — Bad Rabbit (report)
  • Kaspersky — 82851 (report)
  • intezer.com — Notpetya Returns Bad Rabbit (report)
  • securityandtechnology.org — Ist Ransomware Task Force Final Report (report)
  • fortinet.com — The Increasing Wiper Malware Threat (report)
  • youtube.com — Watch (report)
  • ESET — New Telebots Backdoor Linking Industroyer Notpetya (report)
  • tesorion.nl — Report Osint Russia Ukraine Conflict Cyberaspect (report)
  • Kaspersky — 97239 (report)
  • Cisco Talos — Current Executive Guidance For Ongoing (report)
  • CISA — Aa22 110A Joint Csa Russian State Sponsored And Criminal Cyber Threats To Critical Infrastructure 4 20 22 Final (report)
  • cyberpeaceinstitute.org — Ukraine Timeline Of Cyberattacks (report)
  • ironnet.com — Russian Cyber Attack Campaigns And Actors (report)

External references