Skip to content

Petya

Petya is a Windows disk-encrypting ransomware family first observed in March 2016.

Petya

Family profile

Petya is a Windows disk-encrypting ransomware family first observed in March 2016. It was commonly delivered through German-language job-application phishing lures that directed victims to a malicious download. With administrative privileges, Petya overwrites early disk boot sectors with a custom bootloader and forces a reboot. Before Windows loads, the bootloader presents a fake disk-check screen and encrypts the NTFS Master File Table, rendering files inaccessible while generally leaving their underlying contents on disk. It subsequently displays a ransom screen, including its characteristic skull imagery. Petya’s privilege requirement led its operators to deploy Mischa, a conventional user-mode file-encrypting ransomware, as a fallback payload; the two were later combined in the GoldenEye campaign. Petya is distinct from the destructive 2017 NotPetya outbreak, despite substantial bootloader and MBR-related similarities that initially caused widespread naming confusion.

Capabilities

  • Persistence

Samples

Recent samples

6 sandbox samples in the Derp library, newest 6 shown

Reported operators

Threat actors

4 named in public reporting
Cobalt Group

hackers used a self-developed modification of Petya ransomware named PetrWrap.

Shadow Brokers

This is a follow-up from our previous diary about today's ransomware attacks using the new Petya variant... Petya is a ransomware family that works by modifying the infected Windows system's Master Boot Record (MBR).

Sandworm

While the world is holding its breath, wondering where notorious cybercriminal groups like Lazarus or Telebots will strike next with another destructive malware such as WannaCryptor or Petya...

Janus

When Petya spread for the first time in March 2016... After a reboot the Master File Tabel (MFT) is encrypted... The evident similarity to Petya caused many researchers to name the new threat "Petya", too. But first doubts emerged soon, which are reflected in names like NotPetya, Nyetya, or Petna.

Exploited software

Vulnerabilities linked to Petya

4 CVEs

MITRE ATT&CK

Petya in ATT&CK

56 distinct techniques

Techniques

56 techniques
T1486 Data Encrypted for Impact T1021.002 SMB/Windows Admin Shares T1047 Windows Management Instrumentation T1195 Supply Chain Compromise T1070 Indicator Removal T1003 OS Credential Dumping T1053 Scheduled Task/Job T1555 Credentials from Password Stores T1048 Exfiltration Over Alternative Protocol T1135 Network Share Discovery T1021 Remote Services T1203 Exploitation for Client Execution T1105 Ingress Tool Transfer T1210 Exploitation of Remote Services T1566.001 Spearphishing Attachment T1561.001 Disk Content Wipe T1529 System Shutdown/Reboot T1036 Masquerading T1134 Access Token Manipulation T1055 Process Injection T1561 Disk Wipe T1543 Create or Modify System Process T1218.011 Rundll32 T1559.001 Component Object Model T1542.001 System Firmware T1070.004 File Deletion T1016 System Network Configuration Discovery T1570 Lateral Tool Transfer T1189 Drive-by Compromise T1548.002 Bypass User Account Control T1620 Reflective Code Loading T1497 Virtualization/Sandbox Evasion T1120 Peripheral Device Discovery T1566 Phishing T1566.002 Spearphishing Link T1027.002 Software Packing T1548 Abuse Elevation Control Mechanism T1046 Network Service Discovery T1204 User Execution T1027 Obfuscated Files or Information T1083 File and Directory Discovery T1071 Application Layer Protocol T1082 System Information Discovery T1140 Deobfuscate/Decode Files or Information T1685.005 Clear Windows Event Logs T1053.005 Scheduled Task T1542.003 Bootkit T1078 Valid Accounts T1498 Network Denial of Service T1485 Data Destruction T1195.002 Compromise Software Supply Chain T1601 Modify System Image T1542 Pre-OS Boot T1021.001 Remote Desktop Protocol T1569.002 Service Execution T1490 Inhibit System Recovery

Reporting

Research mentioning Petya

Mar 22
Sentinelone Labs Subdomain

Multi-Platform SMAUG RaaS Aims To See Off Competitors - SentinelLabs

SMAUG is a ransomware-as-a-service (RaaS) operation that advertises 64-bit payloads for Windows, Linux, and macOS, positioning itself as a multi-platform option for affiliates. The service reportedly charges a 20% affiliate fee plus a 0.2 BTC registration fee, and provides a web-based campaign builder, customizable ransom demands, offline encryption, and a "Company Mode" that allows a single decryption key to unlock multiple systems inside one targeted organization. Victims are directed to a Tor-based payment portal, while operators reportedly offer automated support for both affiliates and victims and bar attacks against CIS countries. On Windows, SMAUG uses obfuscated Go binaries that gather system details and stored browser credentials, establish persistence through Registry Run Keys consistent with MITRE ATT&CK T1547.001, and then encrypt files for impact using AES-256 with keys protected by RSA-2048, aligning with T1486 Data Encrypted for Impact tradecraft. The combination of credential collection, registry-based autostart, and hybrid cryptography reflects a mature ransomware model designed to support repeatable intrusions and broad enterprise targeting across multiple operating systems.

May 13
Securelist

Petya: the two-in-one trojan | Securelist

The Petya ransomware family used German-language job-application phishing emails, often linking to ZIP archives hosted on Dropbox, to infect primarily HR staff in German-speaking countries. Once launched, Petya sought elevated privileges through a Windows UAC prompt, unpacked a malicious Setup.dll, overwrote boot structures including the MBR, and encrypted the NTFS Master File Table, leaving systems unable to boot normally or access files after a forced reboot. The malware used a Tor-based payment site, victim identifiers, and a cryptographic workflow involving elliptic-curve cryptography, AES, Base58, and Salsa20. To improve infection success, the operators added Mischa as a fallback payload for cases where administrator rights were not obtained. Unlike Petya, Mischa could encrypt files without elevated privileges, worked offline, targeted a wide range of file types across fixed, removable, and remote drives, and used reflective DLL injection into conhost.exe. Researchers later described this dual-payload approach as evolving into GoldenEye, while noting that Mischa’s conventional file encryption could be harder to reverse through forensic recovery than Petya’s disk-level attack; the campaigns were widely linked to actors operating under the name Janus.

Feb 28
Symantec Broadcom

Chafer: Latest Attacks Reveal Heightened Ambitions | SECURITY.COM

The Iran-linked Chafer threat group broadened its surveillance-focused intrusion campaign by compromising nine additional organizations across the Middle East and beyond, including targets in telecommunications, airlines, aircraft services, IT services, payroll, engineering, and document management. Symantec reported that the group breached a major regional telecom services provider and also attempted to penetrate a large international travel reservations company, indicating a wider operational scope and growing ambition beyond its earlier victim set. Chafer used spear-phishing Excel documents to launch infections that dropped VBS and PowerShell payloads, then deployed information-stealing and screen-capture malware before moving laterally inside victim networks. The operators also expanded their toolkit with utilities and infrastructure including Remcom, NSSM, UltraVNC, NBTScan, GNU HTTPTunnel, EternalBlue-enabled SMB tooling, and the command-and-control domain win7-updates[.]com; researchers also noted overlaps with Crambus/Oilrig in infrastructure and infection chains, though they said the evidence was insufficient to conclude the groups were the same.

Jul 3
G Data Software

Who is behind Petna?

Sep 20
Avast

Inside Petya and Mischa ransomware

Jun 9
Malwarebytes Labs

Petya and Mischa: ransomware duet (part 2) | Malwarebytes Labs