Petya
Aliases: Goldeneye
- First seen
- 2016-03-04 00:00:00
- Malware type
- ransomware, wiper
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:55:25
- Profile updated
- 2026-07-07 15:42:54
Targeted industries: energy-and-utilities financial-services government-and-public-sector healthcare-and-pharmaceutical manufacturing transportation-and-logistics
Targeted regions: country_code:ua country_code:de
Context
Ransomware encrypts disk partitions PDFBewerbungsmappe.exe
Detection coverage
- 3 YARA rules
Detection rules
- MALPEDIA_Win_Petya_Auto (yara-rule)
- MALPEDIA_Win_Eternal_Petya_Auto (yara-rule)
- CAPE_Petya (yara-rule)
Related threat objects
- GoldenEye Ransomware (malware)
Reports & references
- bleepingcomputer.com — Petya Ransomware Returns With Goldeneye Version Continuing James Bond Theme (report)
- thewindowsclub.com — Petya Ransomware Decrypt Tool Password Generator (report)
- youtube.com — Watch (report)
- blog.malwarebytes.org — Petya Ransomware (report)
- ransomlook.io — Petya (report)
- Trend Micro — The Impact Of Modern Ransomware On Manufacturing Networks (report)
- CrowdStrike — The Anatomy Of Wiper Malware Part 1 (report)
- CrowdStrike — The Anatomy Of Wiper Malware Part 3 (report)
- blog.malwarebytes.com — Keeping Up With The Petyas Demystifying The Malware Family (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Petya (report)
- blog.malwarebytes.com — Petya Ransomware (report)
- blogs.blackberry.com — Petya And Mischa For All The Raas Boom Expands To Include The Petya Mischa Combo (report)
- malwarebytes.com — Petya And Mischa Ransomware Duet P2 (report)
- blogs.blackberry.com — Petya And Mischa For All Part Ii Theyre Here (report)
- blog.malwarebytes.com — Bye Bye Petya Decryptor Old Versions Released (report)
- blog.malwarebytes.com — Petya And Mischa Ransomware Duet P1 (report)
- Microsoft — New Ransomware Old Techniques Petya Adds Worm Capabilities (report)
- blog.malwarebytes.com — Third Time Unlucky Improved Petya Is Out (report)
- blog.avast.com — Inside Petya And Mischa Ransomware (report)
- Kaspersky — 74609 (report)