PetrWrap

Malware type
ransomware, trojan
Profile updated
2026-07-07 13:24:24

Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector transportation-and-logistics energy-and-utilities

Context

The PetrWrap Trojan is written in C and compiled in MS Visual Studio. It carries a sample of the Petya ransomware v3 inside its data section and uses Petya to infect the victim’s machine. What’s more, PetrWrap implements its own cryptographic routines and modifies the code of Petya in runtime to control its execution. This allows the criminals behind PetrWrap to hide the fact that they are using Petya during infection.

Detection coverage

  • 2 YARA rules

Detection rules

  • CAPE_Petrwrap (yara-rule)
  • MALPEDIA_Win_Petrwrap_Auto (yara-rule)

Reports & references

  • Kaspersky — Petrwrap The New Petya Based Ransomware Used In Targeted Attacks (report)
  • blog.malwarebytes.com — Keeping Up With The Petyas Demystifying The Malware Family (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Petrwrap (report)

External references