hackers used a self-developed modification of Petya ransomware named PetrWrap.
Petya
Petya is a Windows disk-encrypting ransomware family first observed in March 2016.
Petya
Family profile
Petya is a Windows disk-encrypting ransomware family first observed in March 2016. It was commonly delivered through German-language job-application phishing lures that directed victims to a malicious download. With administrative privileges, Petya overwrites early disk boot sectors with a custom bootloader and forces a reboot. Before Windows loads, the bootloader presents a fake disk-check screen and encrypts the NTFS Master File Table, rendering files inaccessible while generally leaving their underlying contents on disk. It subsequently displays a ransom screen, including its characteristic skull imagery. Petya’s privilege requirement led its operators to deploy Mischa, a conventional user-mode file-encrypting ransomware, as a fallback payload; the two were later combined in the GoldenEye campaign. Petya is distinct from the destructive 2017 NotPetya outbreak, despite substantial bootloader and MBR-related similarities that initially caused widespread naming confusion.
Capabilities
- Persistence
Samples
Recent samples
6 sandbox samples in the Derp library, newest 6 shown
224344c4d1c71b2fc9fe76fbef2635f60aa0244d9d2080dca870a9cb6da10d9d 8871f6420737d19b9b042084523549bbe0325921da3ea70df175c298612c26f2 4c1dc737915d76b7ce579abddaba74ead6fdb5b519a1ea45308b8c49b950655c 33ca487a65d38bad82dccfa0d076bad071466e4183562d0b1ad1a2e954667fe9 54942b5bcfc9add448903934fc61f4e02bf2dc6378a65f0aa4af346e858fe9d3 5334b3ffc7256b19783fd5f6049eec85970bdd2511fd9d5176282d5a15d1104d Reported operators
Threat actors
4 named in public reportingThis is a follow-up from our previous diary about today's ransomware attacks using the new Petya variant... Petya is a ransomware family that works by modifying the infected Windows system's Master Boot Record (MBR).
While the world is holding its breath, wondering where notorious cybercriminal groups like Lazarus or Telebots will strike next with another destructive malware such as WannaCryptor or Petya...
When Petya spread for the first time in March 2016... After a reboot the Master File Tabel (MFT) is encrypted... The evident similarity to Petya caused many researchers to name the new threat "Petya", too. But first doubts emerged soon, which are reflected in names like NotPetya, Nyetya, or Petna.
Exploited software
Vulnerabilities linked to Petya
4 CVEsMITRE ATT&CK
Petya in ATT&CK
56 distinct techniquesTechniques
56 techniquesReporting
Research mentioning Petya
Multi-Platform SMAUG RaaS Aims To See Off Competitors - SentinelLabs
SMAUG is a ransomware-as-a-service (RaaS) operation that advertises 64-bit payloads for Windows, Linux, and macOS, positioning itself as a multi-platform option for affiliates. The service reportedly charges a 20% affiliate fee plus a 0.2 BTC registration fee, and provides a web-based campaign builder, customizable ransom demands, offline encryption, and a "Company Mode" that allows a single decryption key to unlock multiple systems inside one targeted organization. Victims are directed to a Tor-based payment portal, while operators reportedly offer automated support for both affiliates and victims and bar attacks against CIS countries. On Windows, SMAUG uses obfuscated Go binaries that gather system details and stored browser credentials, establish persistence through Registry Run Keys consistent with MITRE ATT&CK T1547.001, and then encrypt files for impact using AES-256 with keys protected by RSA-2048, aligning with T1486 Data Encrypted for Impact tradecraft. The combination of credential collection, registry-based autostart, and hybrid cryptography reflects a mature ransomware model designed to support repeatable intrusions and broad enterprise targeting across multiple operating systems.
Petya: the two-in-one trojan | Securelist
The Petya ransomware family used German-language job-application phishing emails, often linking to ZIP archives hosted on Dropbox, to infect primarily HR staff in German-speaking countries. Once launched, Petya sought elevated privileges through a Windows UAC prompt, unpacked a malicious Setup.dll, overwrote boot structures including the MBR, and encrypted the NTFS Master File Table, leaving systems unable to boot normally or access files after a forced reboot. The malware used a Tor-based payment site, victim identifiers, and a cryptographic workflow involving elliptic-curve cryptography, AES, Base58, and Salsa20. To improve infection success, the operators added Mischa as a fallback payload for cases where administrator rights were not obtained. Unlike Petya, Mischa could encrypt files without elevated privileges, worked offline, targeted a wide range of file types across fixed, removable, and remote drives, and used reflective DLL injection into conhost.exe. Researchers later described this dual-payload approach as evolving into GoldenEye, while noting that Mischa’s conventional file encryption could be harder to reverse through forensic recovery than Petya’s disk-level attack; the campaigns were widely linked to actors operating under the name Janus.
Chafer: Latest Attacks Reveal Heightened Ambitions | SECURITY.COM
The Iran-linked Chafer threat group broadened its surveillance-focused intrusion campaign by compromising nine additional organizations across the Middle East and beyond, including targets in telecommunications, airlines, aircraft services, IT services, payroll, engineering, and document management. Symantec reported that the group breached a major regional telecom services provider and also attempted to penetrate a large international travel reservations company, indicating a wider operational scope and growing ambition beyond its earlier victim set. Chafer used spear-phishing Excel documents to launch infections that dropped VBS and PowerShell payloads, then deployed information-stealing and screen-capture malware before moving laterally inside victim networks. The operators also expanded their toolkit with utilities and infrastructure including Remcom, NSSM, UltraVNC, NBTScan, GNU HTTPTunnel, EternalBlue-enabled SMB tooling, and the command-and-control domain win7-updates[.]com; researchers also noted overlaps with Crambus/Oilrig in infrastructure and infection chains, though they said the evidence was insufficient to conclude the groups were the same.