Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors notpetya

Also known as: Telebots, tracked as, Petya, resulting from the compro, Sandworm

Description

NotPetya originated from a compromised update chain of the Ukrainian tax‑processing software M.E.Doc, which delivered a dropper that deployed DLL components such as perfc.dat and dllhost.dat. The payload is launched via rundll32.exe under privileged contexts, enabling execution of PowerShell scripts and WMI commands. Subsequent propagation leverages SMBv1 exploitation (EternalBlue CVE‑2017‑0144 and EternalRomance) along with PsExec and WMIC toolchains to copy itself across administrative shares and elevate privileges through impersonation of user tokens and SeShutdown/SeDebug rights. During infection the malware harvests credentials using a custom Mimikatz module that dumps LSASS memory (T1003.001). It then performs extensive discovery—file and directory enumeration, software detection—and checks for running antivirus processes to adapt its behavior. To evade detection it clears Windows event logs with wevtutil and creates scheduled tasks that trigger system reboots via the NtRaiseHardError API. The destructive core of NotPetya operates in three stages: (1) encrypting user documents with AES‑128 or RSA‑2048 keys, (2) encrypting the Master File Table using Salsa20 with freshly generated keys, and (3) overwriting the Master Boot Record to inject a custom bootloader. No decryption mechanism is provided, rendering affected hosts irrecoverably damaged unless restored from backups. Alongside the wiper functionality the malware incorporates a persistent backdoor that uses XML‑based configuration to communicate securely over HTTPS with command–and–control servers. The combination of supply‑chain compromise, SMB lateral movement, credential harvesting, and destructive payloads enabled NotPetya to devastate both corporate networks and industrial control systems globally.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Government
Financial services
Education
Energy
Transportation
Manufacturing
Healthcare
Critical infrastructure
Media

Targeted Countries / Regions

UA
RU
US
GB
CN

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 14 hours ago

Executive Summary

NotPetya is a destructive malware weapon introduced on 27 June 2017 and attributed to the Russian GRU Sandworm unit. It masquerades as ransomware but delivers irreversible damage by encrypting files, MFT, and overwriting the Master Boot Record, while using SMBv1 exploits (EternalBlue/EternalRomance) for rapid lateral spread across critical infrastructure sectors worldwide.

Goals & Targeting

The Sandworm group appears driven by state-sponsored objectives rather than pure monetary gain; the campaign was designed as a strategic sabotage tool aimed at disrupting Ukrainian targets and demonstrating the Kremlin’s cyber‑weapon capabilities. By attacking sectors such as government, financial services, energy, transportation, manufacturing, healthcare, education, media, and critical infrastructure, the actor sought to amplify political influence and showcase its proficiency in deploying wiper malware that transcends typical ransomware economics.

Enhanced Description

Key Capabilities

  • Lateral movement via SMBv1 exploits (EternalBlue CVE‑2017‑0144, EternalRomance) using admin shares
  • Remote execution propagation through PsExec, WMIC, PowerShell and WMI scripts
  • Credential harvesting with a modified Mimikatz module (LSASS memory dumps)
  • Destructive data encryption of user files (AES‑128/2048‑bit RSA), Master File Table, and Master Boot Record
  • Clearing Windows event logs using wevtutil to erase forensic footprints
  • Detection evasion by probing for antivirus processes and disabling security tools
  • Backdoor persistence via HTTPS‑based XML configuration communicating with remote C&C
  • Supply‑chain compromised distribution through malicious updates of M.E.Doc tax software

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Discovery
Defense Evasion
Impact
Lateral Movement

ATT&CK Techniques

T1083
T1003.001
T1518
T1053.005
T1070.003
T1021.001
T1047
T1218

Software / Tooling

NotPetya
Petya
EternalBlue
EternalRomance
PsExec
Mimikatz
rundll32.exe
WMIC
TeleBots backdoor
M.E.Doc
Industroyer
Diskcoder.C
Exaramel (Win32/Exaramel backdoor)

Campaigns & Victims

Since its onset in June 2017, NotPetya has displayed a blend of supply‑chain exploitation and ubiquitous lateral movement exploiting widely known SMB vulnerabilities. While the initial foothold came from compromised tax‐software updates in Ukraine, the malware rapidly propagated into enterprise and industrial networks worldwide, including critical infrastructure such as energy grids. Its destructive payload eclipsed traditional ransomware business models, underscoring its role as a state‑grade sabotage tool rather than purely financial crime. Subsequent operations—e.g., BlackEnergy, ITRIX, Industroyer—show code reuse and shared techniques, indicating an evolving cyber‑weapon arsenal maintained by the same group.

IOC Patterns

  • file hash MD5
  • file hash SHA256
  • domain name
  • IP address v4
  • file name
  • DLL name
  • scheduled task creation syntax
  • SMB exploit activity indicator
  • credential dumping pattern

Recommended Actions

  • Patch or disable SMBv1 and remediate EternalBlue/EternalRomance CVEs (CVE‑2017‑0144/0143).
  • Block exploitation traffic for CVE‑2017‑0144 and CVE‑2017‑0143 at perimeter firewalls.
  • Monitor and alert on unauthorized use of PsExec, WMIC, rundll32.exe, PowerShell scripts, and scheduled task creation.
  • Enforce strict controls on privileged account usage, including mandatory MFA for administrative accounts.
  • Protect Windows event logs by disabling clearing permissions and regularly back them up to immutable storage.
  • Maintain offline or geographically isolated backups of critical systems and data.
  • Isolate any infected host immediately, halt lateral spread, and rebuild from clean, signed images.
  • Deploy a managed SOC to detect indicators such as Mimikatz signatures, DLL hijacking patterns, and anomalous SMB activity.
  • Conduct regular phishing and supply‑chain awareness training for all users.

Suggested Tags

NotPetya
Wiper Malware
Ransomware Misnomer
Sandworm
GRU
Cyberweapon
SMB Vulnerabilities
EternalBlue
Mimikatz
Credential Dumping
Industrial Disruption
TeleBots Backdoor
Industroyer
Critical Infrastructure
Government Targeting
Financial Services
Energy Sector
Transportation
Manufacturing
Healthcare
Education
Media
State-sponsored
Russia
Ukraine
Supply Chain Compromise

Confidence Assessment

The technical behaviors and supply‑chain vector of NotPetya are well documented through open‑source analysis, providing high confidence in the described capabilities. Attribution to the Russian GRU Sandworm unit is supported by multiple independent reports, but some intelligence gaps remain regarding internal chain‑of‑command details, post‑infection backdoor persistence, and whether current operations still employ this exact malware family.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

MD5 Hash 4 SHA-256 Hash 3 Domain 9 Filename 3 IPv4 Address 1

References

Intel Summary

23

Techniques

55

Tools

0

Campaigns

40

IOCs

0

Observed Data

9

Tactics

Tags

Russia
GRU
Sandworm
Wiper
Ransomware-like
Supply-Chain Compromise
SMB Exploit
EternalBlue
MTEF
Credential Dumping
Industrial Control Systems
State‑backed
Nationalism
Infrastructure Disruption
Phishing PDF
NotPetya
Wiper Malware
Ransomware Misnomer
Cyberweapon
SMB Vulnerabilities
Mimikatz
Industrial Disruption
TeleBots Backdoor
Industroyer
Critical Infrastructure
Government Targeting
Financial Services
Energy Sector
Transportation
Manufacturing
Healthcare
Education
Media
State-sponsored
Ukraine
Supply Chain Compromise

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
Russia (RU)
Confidence
80%
First Seen
Jan 1, 2017
Last Seen
Jan 1, 2017
Added
Jul 30, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.