NotPetya
MITRE ATT&CK: S0368 View on attack.mitre.org
Aliases: ExPetr, Diskcoder.C, GoldenEye, Petrwrap, Nyetya, BadRabbit, NonPetya, NotPetya, Petna, Pnyetya, nPetya
- First seen
- 2017-06-27 00:00:00
- Malware type
- wiper, worm, ransomware
- Family
- Malware family
- Operating systems
- windows
- Last IoC activity
- 2026-07-20 13:15:03
- Profile updated
- 2026-07-07 12:44:42
Targeted industries: government-and-public-sector financial-services energy-and-utilities transportation-and-logistics healthcare-and-pharmaceutical manufacturing
Targeted regions: country_code:ua country_code:ru country_code:us country_code:gb country_code:fr country_code:de
Context
NotPetya is malware that was used by Sandworm Team in a worldwide attack starting on June 27, 2017. While NotPetya appears as a form of ransomware, its main purpose was to destroy data and disk structures on compromised systems; the attackers never intended to make the encrypted data recoverable. As such, NotPetya may be more appropriately thought of as a form of wiper malware. NotPetya contains worm-like features to spread itself across a computer network using the SMBv1 exploits EternalBlue and EternalRomance.
Detection coverage
- 4 YARA rules
- 356 Sigma rules
Malware & tools used
- Service Execution (attack-pattern)
- Scheduled Task (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- Security Software Discovery (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Exploitation of Remote Services (attack-pattern)
- File and Directory Discovery (attack-pattern)
- LSASS Memory (attack-pattern)
- System Shutdown/Reboot (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Masquerading (attack-pattern)
- Rundll32 (attack-pattern)
- Local Accounts (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- Exploitation of Remote Services (attack-pattern)
- Loss of Productivity and Revenue (attack-pattern)
Used by threat actors
- Sandworm Team (threat-actor)
Detection rules
- CAPE_Badrabbit (yara-rule)
- CAPE_Petrwrap (yara-rule)
- MALPEDIA_Win_Petrwrap_Auto (yara-rule)
- SEKOIA_Apt_Sandworm_Notpetya_Strings (yara-rule)
Related threat objects
- Bad Rabbit (malware)
Reports & references
- MITRE ATT&CK — G0034 (report)
- ESET — Telebots Back Supply Chain Attacks Against Ukraine (report)
- ESET — New Ransomware Attack Hits Ukraine (report)
- ESET — Bad Rabbit Not Petya Back (report)
- services.google.com — Apt44 Unearthing Sandworm (report)
- CISA — Aa22 110A (report)
- Kaspersky — 91897 (report)
- Kaspersky — 97937 (report)
- Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
- gov.uk — Uk Exposes Series Of Russian Cyber Attacks Against Olympic And Paralympic Games (report)
- justice.gov — Download (report)
- secureworks.com — Iron Viking (report)
- Cisco Talos — Bad Rabbit (report)
- Kaspersky — 82851 (report)
- intezer.com — Notpetya Returns Bad Rabbit (report)
- securityandtechnology.org — Ist Ransomware Task Force Final Report (report)
- fortinet.com — The Increasing Wiper Malware Threat (report)
- youtube.com — Watch (report)
- ESET — New Telebots Backdoor Linking Industroyer Notpetya (report)
- tesorion.nl — Report Osint Russia Ukraine Conflict Cyberaspect (report)
- Kaspersky — 97239 (report)
- Cisco Talos — Current Executive Guidance For Ongoing (report)
- CISA — Aa22 110A Joint Csa Russian State Sponsored And Criminal Cyber Threats To Critical Infrastructure 4 20 22 Final (report)
- cyberpeaceinstitute.org — Ukraine Timeline Of Cyberattacks (report)
- ironnet.com — Russian Cyber Attack Campaigns And Actors (report)
External references
- mitre-attack — S0368
- ExPetr
- Diskcoder.C
- GoldenEye
- Nyetya
- Petrwrap
- ESET Telebots June 2017
- Talos Nyetya June 2017
- US District Court Indictment GRU Unit 74455 October 2020
- US-CERT NotPetya 2017
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy