Also known as: Telebots, tracked as, Petya, resulting from the compro, Sandworm
NotPetya originated from a compromised update chain of the Ukrainian tax‑processing software M.E.Doc, which delivered a dropper that deployed DLL components such as perfc.dat and dllhost.dat. The payload is launched via rundll32.exe under privileged contexts, enabling execution of PowerShell scripts and WMI commands. Subsequent propagation leverages SMBv1 exploitation (EternalBlue CVE‑2017‑0144 and EternalRomance) along with PsExec and WMIC toolchains to copy itself across administrative shares and elevate privileges through impersonation of user tokens and SeShutdown/SeDebug rights. During infection the malware harvests credentials using a custom Mimikatz module that dumps LSASS memory (T1003.001). It then performs extensive discovery—file and directory enumeration, software detection—and checks for running antivirus processes to adapt its behavior. To evade detection it clears Windows event logs with wevtutil and creates scheduled tasks that trigger system reboots via the NtRaiseHardError API. The destructive core of NotPetya operates in three stages: (1) encrypting user documents with AES‑128 or RSA‑2048 keys, (2) encrypting the Master File Table using Salsa20 with freshly generated keys, and (3) overwriting the Master Boot Record to inject a custom bootloader. No decryption mechanism is provided, rendering affected hosts irrecoverably damaged unless restored from backups. Alongside the wiper functionality the malware incorporates a persistent backdoor that uses XML‑based configuration to communicate securely over HTTPS with command–and–control servers. The combination of supply‑chain compromise, SMB lateral movement, credential harvesting, and destructive payloads enabled NotPetya to devastate both corporate networks and industrial control systems globally.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
NotPetya is a destructive malware weapon introduced on 27 June 2017 and attributed to the Russian GRU Sandworm unit. It masquerades as ransomware but delivers irreversible damage by encrypting files, MFT, and overwriting the Master Boot Record, while using SMBv1 exploits (EternalBlue/EternalRomance) for rapid lateral spread across critical infrastructure sectors worldwide.
Goals & Targeting
The Sandworm group appears driven by state-sponsored objectives rather than pure monetary gain; the campaign was designed as a strategic sabotage tool aimed at disrupting Ukrainian targets and demonstrating the Kremlin’s cyber‑weapon capabilities. By attacking sectors such as government, financial services, energy, transportation, manufacturing, healthcare, education, media, and critical infrastructure, the actor sought to amplify political influence and showcase its proficiency in deploying wiper malware that transcends typical ransomware economics.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its onset in June 2017, NotPetya has displayed a blend of supply‑chain exploitation and ubiquitous lateral movement exploiting widely known SMB vulnerabilities. While the initial foothold came from compromised tax‐software updates in Ukraine, the malware rapidly propagated into enterprise and industrial networks worldwide, including critical infrastructure such as energy grids. Its destructive payload eclipsed traditional ransomware business models, underscoring its role as a state‑grade sabotage tool rather than purely financial crime. Subsequent operations—e.g., BlackEnergy, ITRIX, Industroyer—show code reuse and shared techniques, indicating an evolving cyber‑weapon arsenal maintained by the same group.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The technical behaviors and supply‑chain vector of NotPetya are well documented through open‑source analysis, providing high confidence in the described capabilities. Attribution to the Russian GRU Sandworm unit is supported by multiple independent reports, but some intelligence gaps remain regarding internal chain‑of‑command details, post‑infection backdoor persistence, and whether current operations still employ this exact malware family.
No campaigns linked yet.
No observed data linked yet.
23
Techniques
55
Tools
0
Campaigns
40
IOCs
0
Observed Data
9
Tactics