Skip to content

NotPetya

NotPetya is malware that initially appeared to be ransomware but was later identified as a destructive wiper.

Profile source: Mallory opens in a new tab

NotPetya

Family profile

NotPetya is malware that initially appeared to be ransomware but was later identified as a destructive wiper. The provided content states that it spread globally on 2017-06-27, used the EternalBlue vulnerability, and was attributed to Russian state-sponsored actors, specifically Sandworm / the Russian GRU. It is described as specifically targeting Ukrainian users and as being delivered through a supply-chain compromise of the M.E.Doc update mechanism, making it one of the most damaging supply-chain incidents cited in the content. The content also notes that its early activity drew comparisons to WannaCry because both leveraged EternalBlue. High-confidence behaviors and context directly mentioned here are destructive impact, pseudo-ransomware presentation, global propagation, exploitation of EternalBlue, and distribution via the compromised M.E.Doc software update channel. The content does not provide specific file hashes, domains, IPs, or other concrete IOCs.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.