NotPetya, also known as Nyetya, ExPetr, PetrWrap, and DiskCoder.C, was a destructive malware operation that masqueraded as ransomware while functioning primarily as a wiper. It is widely attributed to the Russian GRU’s Sandworm unit and is most closely associated with the 2017 attack that began in Ukraine and caused major global disruption. The malware was distributed through the compromised update mechanism of the widely used Ukrainian M.E.Doc accounting software, making it a canonical example of a destructive software supply-chain attack.
Although presented as ransomware, NotPetya was designed to render infected Windows systems inoperable rather than support reliable recovery. It targeted boot-level and file-system structures in ways that prevented normal system operation and made restoration through ransom payment effectively impossible. Its deceptive ransomware presentation likely served to delay accurate incident response and misdirect defenders during the early stages of the outbreak.
NotPetya spread rapidly through enterprise environments and caused severe collateral damage well beyond its initial Ukraine-focused targeting. Impacted sectors included shipping, logistics, finance, manufacturing, pharmaceuticals, government services, and commercial administration. The incident is regarded as one of the most consequential destructive cyberattacks on record because of its operational disruption, global spillover, and economic cost.
The malware is strongly linked to Sandworm, also tracked as GRU Unit 74455 or APT44, a Russian state actor associated with disruptive and destructive operations against Ukraine and other targets. NotPetya remains a landmark case in cyber conflict because it demonstrated how a state-directed attack on a trusted civilian software dependency could produce strategic effects across international private-sector and government networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Among the exposed tools was EternalBlue, a collection of Windows zero-day vulnerabilities that enabled attackers to infiltrate systems, move laterally across networks, and spread malware automatically. The leaked EternalBlue exploit later became the foundation for some of the most destructive cyberattacks ever recorded. North Korean hackers used it in the WannaCry ransomware outbreak, while Russian operators incorporated it into the NotPetya malware campaign. | ...while Russian operators incorporated it into the NotPetya malware campaign. Although initially aimed at targets in Ukraine, NotPetya spread globally and is estimated to have caused around $10 billion in economic losses.
Dillon has crafted his modified exploits to take advantage of the following vulnerabilities: CVE-2017-0143 Type confusion between WriteAndX and Transaction requests EternalRomance EternalSynergy
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
NotPetya represents one of the strongest examples of functional defeat. Although presented as ransomware, the malware was designed to render systems inoperable.
2017 Globalized destructive spillover NotPetya Ukraine-targeted operations could create global collateral damage and strategic economic effects.
The GRU’s malign cyber activities include deployment of the NotPetya and Olympic Destroyer malware; intrusions targeting the Organization for the Prohibition of Chemical Weapons and the World Anti-Doping Agency; cyber attacks on government systems and critical infrastructure in Ukraine and the state of Georgia; and hack-and-leak operations targeting elections in the United States and France.
This group has been behind several cyber-attacks aimed at Ukraine in the past, such as the NotPetya ransomware outbreak, and the BlackEnergy attacks on Ukraine's power grid in 2015 and 2016.
The Trump administration on Thursday publicly blamed Russia for the massive notPetya cyberattack that ravaged computer systems worldwide last June... “The attack, dubbed ‘NotPetya,’ quickly spread worldwide, causing billions of dollars in damage across Europe, Asia, and the Americas,” the White House said.
The business made use of specific websites for customer project tracking and data sharing. This was variously referred to as GoldenEye, Commando, or MyCommando, and acted as a place where customers could log in to view and download campaign specific data and status updates, communicate securely, and manage other aspects of their projects.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
the defendants and their co-conspirators deployed destructive malware and took other disruptive actions, for the strategic benefit of Russia, through unauthorized access to victim computers (hacking).
The prototype worm does not exploit zero-day vulnerabilities. It only targets publicly disclosed but unpatched bugs, misconfigurations, and recurring weakness classes.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
the defendants and their co-conspirators deployed destructive malware and took other disruptive actions, for the strategic benefit of Russia, through unauthorized access to victim computers (hacking).
Sandworm planted a backdoor in an M.E.Doc software update that came to be known as "NotPetya."
North Korean hackers used EternalBlue to unleash the WannaCry ransomware worm. Russian hackers later built it into NotPetya, which spiraled beyond its initial Ukrainian targets and caused an estimated $10 billion in damages globally.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Rather than attacking isolated machines, it disabled the interconnected processes on which organizations depended to operate and recover.
Examples include 'Aquatic Panda used WMI for lateral movement in victim environments,' 'Deep Panda group is known to utilize WMI for lateral movement,' and 'Cinnamon Tempest has used Impacket for lateral movement via WMI.'
Merck’s litigation over NotPetya damages, which the company put at roughly $1.4 billion, tested the war exclusion in “all risks” property policies... Lloyd’s of London had already moved in the same direction, issuing a market bulletin in August 2022 that required standalone cyber policies to explicitly exclude state-backed attacks
Once the attacker has positioned themselves for maximum damage, two things typically happen in quick succession: sensitive data is quietly copied out of the network (exfiltration), and then ransomware payloads are deployed across as many systems as possible simultaneously, encrypting files and displaying a ransom demand. | A ransomware attack is a type of cyberattack in which malicious software encrypts an organization’s files or systems, then demands payment, usually in cryptocurrency, in exchange for the decryption key.
No key even existed to reorder the scrambled noise of their computer’s contents.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive wiper masquerading as ransomware, spread via a compromised Ukrainian tax software update and caused massive global damage.
Destructive malware incident referenced as part of the wave of major cyberattacks that elevated cybersecurity into a major business risk.
Destructive pseudo-ransomware/wiper referenced as a historical case in discussion of cyber conflict history.
Destructive pseudo-ransomware designed to render systems inoperable and cause systemic disruption across interconnected organizations and sectors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.