PetrWrap
- Malware type
- ransomware, trojan
- Profile updated
- 2026-07-07 13:24:24
Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector transportation-and-logistics energy-and-utilities
Context
The PetrWrap Trojan is written in C and compiled in MS Visual Studio. It carries a sample of the Petya ransomware v3 inside its data section and uses Petya to infect the victim’s machine. What’s more, PetrWrap implements its own cryptographic routines and modifies the code of Petya in runtime to control its execution. This allows the criminals behind PetrWrap to hide the fact that they are using Petya during infection.
Detection coverage
- 2 YARA rules
Detection rules
- CAPE_Petrwrap (yara-rule)
- MALPEDIA_Win_Petrwrap_Auto (yara-rule)
Reports & references
- Kaspersky — Petrwrap The New Petya Based Ransomware Used In Targeted Attacks (report)
- blog.malwarebytes.com — Keeping Up With The Petyas Demystifying The Malware Family (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Petrwrap (report)