Petya

Aliases: Goldeneye

First seen
2016-03-04 00:00:00
Malware type
ransomware, wiper
Family
Malware family
Last IoC activity
2026-07-22 01:55:25
Profile updated
2026-07-07 15:42:54

Targeted industries: energy-and-utilities financial-services government-and-public-sector healthcare-and-pharmaceutical manufacturing transportation-and-logistics

Targeted regions: country_code:ua country_code:de

Context

Ransomware encrypts disk partitions PDFBewerbungsmappe.exe

Detection coverage

  • 3 YARA rules

Detection rules

  • MALPEDIA_Win_Petya_Auto (yara-rule)
  • MALPEDIA_Win_Eternal_Petya_Auto (yara-rule)
  • CAPE_Petya (yara-rule)

Related threat objects

Reports & references

  • bleepingcomputer.com — Petya Ransomware Returns With Goldeneye Version Continuing James Bond Theme (report)
  • thewindowsclub.com — Petya Ransomware Decrypt Tool Password Generator (report)
  • youtube.com — Watch (report)
  • blog.malwarebytes.org — Petya Ransomware (report)
  • ransomlook.io — Petya (report)
  • Trend Micro — The Impact Of Modern Ransomware On Manufacturing Networks (report)
  • CrowdStrike — The Anatomy Of Wiper Malware Part 1 (report)
  • CrowdStrike — The Anatomy Of Wiper Malware Part 3 (report)
  • blog.malwarebytes.com — Keeping Up With The Petyas Demystifying The Malware Family (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Petya (report)
  • blog.malwarebytes.com — Petya Ransomware (report)
  • blogs.blackberry.com — Petya And Mischa For All The Raas Boom Expands To Include The Petya Mischa Combo (report)
  • malwarebytes.com — Petya And Mischa Ransomware Duet P2 (report)
  • blogs.blackberry.com — Petya And Mischa For All Part Ii Theyre Here (report)
  • blog.malwarebytes.com — Bye Bye Petya Decryptor Old Versions Released (report)
  • blog.malwarebytes.com — Petya And Mischa Ransomware Duet P1 (report)
  • Microsoft — New Ransomware Old Techniques Petya Adds Worm Capabilities (report)
  • blog.malwarebytes.com — Third Time Unlucky Improved Petya Is Out (report)
  • blog.avast.com — Inside Petya And Mischa Ransomware (report)
  • Kaspersky — 74609 (report)

External references