NotPetya
   HOME

TheInfoList



OR:

Petya is a family of encrypting
malware Malware (a portmanteau of ''malicious software'')Tahir, R. (2018)A study on malware and malware detection techniques . ''International Journal of Education and Management Engineering'', ''8''(2), 20. is any software intentionally designed to caus ...
that was first discovered in 2016. The malware targets
Microsoft Windows Windows is a Product lining, product line of Proprietary software, proprietary graphical user interface, graphical operating systems developed and marketed by Microsoft. It is grouped into families and subfamilies that cater to particular sec ...
–based systems, infecting the
master boot record A master boot record (MBR) is a type of boot sector in the first block of disk partitioning, partitioned computer mass storage devices like fixed disks or removable drives intended for use with IBM PC-compatible systems and beyond. The concept ...
to execute a payload that encrypts a hard drive's file system table and prevents Windows from booting. It subsequently demands that the users make a payment in
Bitcoin Bitcoin (abbreviation: BTC; Currency symbol, sign: ₿) is the first Decentralized application, decentralized cryptocurrency. Based on a free-market ideology, bitcoin was invented in 2008 when an unknown entity published a white paper under ...
in order to regain access to the system. Variants of Petya were first seen in March 2016, which propagated via infected e-mail attachments. In June 2017, a new variant of Petya was used for a global cyberattack, primarily targeting
Ukraine Ukraine is a country in Eastern Europe. It is the List of European countries by area, second-largest country in Europe after Russia, which Russia–Ukraine border, borders it to the east and northeast. Ukraine also borders Belarus to the nor ...
. The new variant propagates via the EternalBlue exploit, which is generally believed to have been developed by the
U.S The United States of America (USA), also known as the United States (U.S.) or America, is a country primarily located in North America. It is a federal republic of 50 U.S. state, states and a federal capital district, Washington, D.C. The 48 ...
.
National Security Agency The National Security Agency (NSA) is an intelligence agency of the United States Department of Defense, under the authority of the director of national intelligence (DNI). The NSA is responsible for global monitoring, collection, and proces ...
(NSA), and was used earlier in the year by the WannaCry ransomware.
Kaspersky Lab Kaspersky Lab (; ) is a Russian multinational cybersecurity and anti-virus provider headquartered in Moscow, Russia, and operated by a holding company in the United Kingdom. It was founded in 1997 by Eugene Kaspersky, Natalya Kaspersky a ...
referred to this new version as ''NotPetya'' to distinguish it from the 2016 variants, due to these differences in operation. It looked like ransomware, but without functioning recovery feature it was equivalent to a wiper. The NotPetya attacks have been blamed on the Russian government, specifically the Sandworm hacking group within the
GRU Gru is a fictional character and the main protagonist of the ''Despicable Me'' film series. Gru or GRU may also refer to: Arts and entertainment * Gru (rapper), Serbian rapper * Gru, an antagonist in '' The Kine Saga'' Organizations Georgia (c ...
Russian military intelligence organization, by security researchers, Google, and several governments.


History

Petya was discovered in March 2016; Check Point noted that while it had achieved fewer infections than other ransomware active in early 2016, such as CryptoWall, it contained notable differences in operation that caused it to be "immediately flagged as the next step in ransomware evolution". Another variant of Petya discovered in May 2016 contained a secondary payload used if the malware cannot achieve
administrator Administrator or admin may refer to: Job roles Computing and internet * Database administrator, a person who is responsible for the environmental aspects of a database * Forum administrator, one who oversees discussions on an Internet forum * N ...
-level access. The name "Petya" is a reference to the 1995
James Bond The ''James Bond'' franchise focuses on James Bond (literary character), the titular character, a fictional Secret Intelligence Service, British Secret Service agent created in 1953 by writer Ian Fleming, who featured him in twelve novels ...
film ''
GoldenEye ''GoldenEye'' is a 1995 spy film, the seventeenth in the List of James Bond films, ''James Bond'' series produced by Eon Productions, and the first to star Pierce Brosnan as the fictional Secret Intelligence Service, MI6 agent James Bond (lit ...
'', wherein ''Petya'' is one of the two Soviet weapon satellites which carry a "Goldeneye"—an atomic bomb detonated in low Earth orbit to produce an
electromagnetic pulse An electromagnetic pulse (EMP), also referred to as a transient electromagnetic disturbance (TED), is a brief burst of electromagnetic energy. The origin of an EMP can be natural or artificial, and can occur as an electromagnetic field, as an ...
. A
Twitter Twitter, officially known as X since 2023, is an American microblogging and social networking service. It is one of the world's largest social media platforms and one of the most-visited websites. Users can share short text messages, image ...
account that '' Heise'' suggested may have belonged to the author of the malware, named "Hue Janus Cybercrime Solutions" after Alec Trevelyan's crime group in ''GoldenEye'', had an avatar with an image of ''GoldenEye'' character Boris Grishenko, a Russian hacker and antagonist in the film played by Scottish actor Alan Cumming. On 30 August 2018, a regional court in Nikopol in the
Dnipropetrovsk Oblast Dnipropetrovsk Oblast (), is an administrative divisions of Ukraine, oblast (province) in simultaneously southern, eastern and central Ukraine, the most important industrial region of the country. It was created on February 27, 1932. Dnipropetro ...
of Ukraine convicted an unnamed Ukrainian citizen to one year in prison after pleading guilty to having spread a version of Petya online.


2017 cyberattack

On 27 June 2017, a major global
cyberattack A cyberattack (or cyber attack) occurs when there is an unauthorized action against computer infrastructure that compromises the confidentiality, integrity, or availability of its content. The rising dependence on increasingly complex and inte ...
began (Ukrainian companies were among the first to state they were being attacked), utilizing a new variant of Petya. On that day,
Kaspersky Lab Kaspersky Lab (; ) is a Russian multinational cybersecurity and anti-virus provider headquartered in Moscow, Russia, and operated by a holding company in the United Kingdom. It was founded in 1997 by Eugene Kaspersky, Natalya Kaspersky a ...
reported infections in France, Germany, Italy, Poland, the United Kingdom, and the United States, but that the majority of infections targeted Russia and Ukraine, where more than 80 companies were initially attacked, including the National Bank of Ukraine. ESET estimated on 28 June 2017 that 80.0% of all infections were in Ukraine, with Germany second hardest hit with about 9%. Russian president
Vladimir Putin Vladimir Vladimirovich Putin (born 7 October 1952) is a Russian politician and former intelligence officer who has served as President of Russia since 2012, having previously served from 2000 to 2008. Putin also served as Prime Minister of Ru ...
's press secretary,
Dmitry Peskov Dmitry Sergeyevich Peskov (, ; born 17 October 1967) is a Russian diplomat serving as the Kremlin Press Secretary, spokesman for President of Russia, Russian president Vladimir Putin since 2012.Constitution Day Constitution Day is a holiday to honour the constitution of a country. Constitution Day is often celebrated on the anniversary of the signing, promulgation or adoption of the constitution, or in some cases, to commemorate the change to constitut ...
. Oleksandr Kardakov, the founder of the Oktava Cyber Protection company, emphasized that the Petya virus stopped a third of Ukraine's economy for three days, resulting in losses of more than 400 million dollars. Kaspersky dubbed this variant "NotPetya", as it has major differences in its operations in comparison to earlier variants.
McAfee McAfee Corp. ( ), formerly known as McAfee Associates, Inc. from 1987 to 1997 and 2004 to 2014, Network Associates Inc. from 1997 to 2004, and Intel Security Group from 2014 to 2017, is an American proprietary software company focused on online ...
engineer Christiaan Beek stated that this variant was designed to spread quickly, and that it had been targeting "complete energy companies, the
power grid ''Power Grid'' is the English-language version of the second edition of the multiplayer German-style board game ''Funkenschlag'', designed by Friedemann Friese and first released in 2004. ''Power Grid'' was released by Rio Grande Games. I ...
, bus stations, gas stations, the airport, and banks". It was believed that the software update mechanism of —a Ukrainian tax preparation program that, according to
F-Secure F-Secure Corporation is a global cyber security and privacy company, which has its headquarters in Helsinki, Finland. The company has offices in Denmark, Finland, France, Germany, India, Italy, Japan, Malaysia, Netherlands, Norway, Poland, Swed ...
analyst Mikko Hyppönen, "appears to be de facto" among companies doing business in the country—had been compromised to spread the malware. Analysis by ESET found that a backdoor had been present in the update system for at least six weeks prior to the attack, describing it as a "thoroughly well-planned and well-executed operation". The developers of M.E.Doc denied that they were entirely responsible for the cyberattack, stating that they too were victims. On 4 July 2017, Ukraine's cybercrime unit seized the company's servers after detecting "new activity" that it believed would result in "uncontrolled proliferation" of malware. Ukraine police advised M.E.Doc users to stop using the software, as it presumed that the backdoor was still present. Analysis of the seized servers showed that software updates had not been applied since 2013, there was evidence of Russian presence, and an employee's account on the servers had been compromised; the head of the units warned that M.E.Doc could be found criminally responsible for enabling the attack because of its negligence in maintaining the security of their servers. IT-businessman, chairman of the supervisory board of the Oktava Capital company Oleksandr Kardakov proposed to create civil cyber defense in Ukraine.


Operation

Petya's payload infects the computer's
master boot record A master boot record (MBR) is a type of boot sector in the first block of disk partitioning, partitioned computer mass storage devices like fixed disks or removable drives intended for use with IBM PC-compatible systems and beyond. The concept ...
(MBR), overwrites the Windows
bootloader A bootloader, also spelled as boot loader or called bootstrap loader, is a computer program that is responsible for booting a computer and booting an operating system. If it also provides an interactive menu with multiple boot choices then it's o ...
, and triggers a restart. Upon startup, the payload encrypts the Master File Table of the
NTFS NT File System (NTFS) (commonly called ''New Technology File System'') is a proprietary journaling file system developed by Microsoft in the 1990s. It was developed to overcome scalability, security and other limitations with File Allocation Tabl ...
file system, and then displays the ransom message demanding a payment made in
Bitcoin Bitcoin (abbreviation: BTC; Currency symbol, sign: ₿) is the first Decentralized application, decentralized cryptocurrency. Based on a free-market ideology, bitcoin was invented in 2008 when an unknown entity published a white paper under ...
. Meanwhile, the computer's screen displays a purportedly output by
chkdsk In computing, CHKDSK (short for "check disk") is a system software, system tool and command (computing), command in DOS and Microsoft Windows (and related operating systems), as well as Digital Research FlexOS, IBM/Toshiba 4690 Operating System, 4 ...
, Windows' file system scanner, suggesting that the hard drive's sectors are being repaired. The original payload required the user to grant it administrative privileges; one variant of Petya was bundled with a second payload, Mischa, which activated if Petya failed to install. Mischa is a more conventional ransomware payload that encrypts user documents, as well as executable files, and does not require administrative privileges to execute. The earlier versions of Petya disguised their payload as a
PDF Portable document format (PDF), standardized as ISO 32000, is a file format developed by Adobe Inc., Adobe in 1992 to present documents, including text formatting and images, in a manner independent of application software, computer hardware, ...
file, attached to an e-mail. United States Computer Emergency Response Team (US-CERT) and National Cybersecurity and Communications Integration Center (NCCIC) released Malware Initial Findings Report (MIFR) about Petya on 30 June 2017. The "NotPetya" variant used in the 2017 attack uses EternalBlue, an exploit that takes advantage of a
vulnerability Vulnerability refers to "the quality or state of being exposed to the possibility of being attacked or harmed, either physically or emotionally." The understanding of social and environmental vulnerability, as a methodological approach, involves ...
in Windows'
Server Message Block Server Message Block (SMB) is a communication protocol used to share files, printers, serial ports, and miscellaneous communications between nodes on a network. On Microsoft Windows, the SMB implementation consists of two vaguely named Windows ...
(SMB) protocol. EternalBlue is generally believed to have been developed by the U.S.
National Security Agency The National Security Agency (NSA) is an intelligence agency of the United States Department of Defense, under the authority of the director of national intelligence (DNI). The NSA is responsible for global monitoring, collection, and proces ...
(NSA); it was leaked in April 2017 and was also used by WannaCry. The malware harvests passwords (using a tweaked build of open-source Mimikatz) and uses other techniques to spread to other computers on the same network, and uses those passwords in conjunction with PSExec to run code on other local computers. Additionally, although it still purports to be ransomware, the encryption routine was modified so that the malware could not technically revert its changes. This characteristic, along with other unusual signs in comparison to WannaCry (including the relatively low unlock fee of US$300, and using a single, fixed Bitcoin wallet to collect ransom payments rather than generating a unique ID for each specific infection for tracking purposes), prompted researchers to speculate that this attack was not intended to be a profit-generating venture, but to damage devices quickly, and ride off the media attention WannaCry received by claiming to be ransomware.


Mitigation

It was found that it may be possible to stop the encryption process if an infected computer is immediately shut down when the fictitious chkdsk screen appears, and a security analyst proposed that creating read-only files named perfc and/or perfc.dat in the Windows installation directory could prevent the payload of the current strain from executing. The email address listed on the ransom screen was suspended by its provider, Posteo, for being a violation of its terms of use. As a result, infected users could not actually send the required payment confirmation to the perpetrator. Additionally, if the computer's filesystem was FAT based, the MFT encryption sequence was skipped, and only the ransomware's message was displayed, allowing data to be recovered trivially. Microsoft had already released patches for supported versions of
Windows Windows is a Product lining, product line of Proprietary software, proprietary graphical user interface, graphical operating systems developed and marketed by Microsoft. It is grouped into families and subfamilies that cater to particular sec ...
in March 2017 to address the EternalBlue vulnerability. This was followed by patches for unsupported versions of Windows (such as
Windows XP Windows XP is a major release of Microsoft's Windows NT operating system. It was released to manufacturing on August 24, 2001, and later to retail on October 25, 2001. It is a direct successor to Windows 2000 for high-end and business users a ...
) in May 2017, in the direct wake of WannaCry. ''Wired'' believed that "based on the extent of damage Petya has caused so far, though, it appears that many companies have put off patching, despite the clear and potentially devastating threat of a similar ransomware spread." Some enterprises may consider it too disruptive to install updates on certain systems, either due to possible downtime or compatibility concerns, which can be problematic in some environments.


Impact

In a report published by ''Wired'', a White House assessment pegged the total damages brought about by NotPetya to more than $10 billion. This assessment was repeated by former Homeland Security advisor Tom Bossert, who at the time of the attack was the most senior cybersecurity focused official in the US government. During the attack initiated on 27 June 2017, the radiation monitoring system at Ukraine's Chernobyl Nuclear Power Plant went offline. Several Ukrainian ministries, banks and metro systems were also affected. It is said to have been the most destructive cyberattack ever. Among those affected elsewhere included British advertising company WPP, Maersk Line, American pharmaceutical company Merck & Co. (internationally doing business as MSD), Russian oil company
Rosneft PJSC Rosneft Oil Company ( stylized as ROSNEFT) is a Russian integrated energy company headquartered in Moscow. Rosneft specializes in the exploration, extraction, production, refining, transport, and sale of petroleum, natural gas, and pet ...
(its oil production was unaffected), multinational law firm
DLA Piper DLA Piper is a law firm with offices in over 40 countries across the Americas, Asia Pacific, Europe, Africa, and the Middle East. It was founded in 2005 through the merger between three law firms: San Diego–based ''Gray Cary Ware & Freiden ...
, French construction company Saint-Gobain and its retail and subsidiary outlets in Estonia, British consumer goods company
Reckitt Benckiser Reckitt Benckiser Group PLC, currently branded as Reckitt, formerly known as Reckitt Benckiser, is a British multinational consumer goods company headquartered in Slough, United Kingdom. It is a producer of health, hygiene and nutrition prod ...
, German personal care company Beiersdorf, German logistics company
DHL DHL (originally named after founders Dalsey, Hillblom and Lynn) is a multinational Import-Export Expert Company, founded in the United States and headquartered in Bonn, Germany. It provides courier, package delivery, and express mail service, ...
, United States food company
Mondelez International Mondelēz International, Inc. ( ) is an American Multinational corporation, multinational confectionery, food industry, food, Holding company, holding, drink industry, beverage and snack food company based in Chicago. Mondelez has an annual rev ...
, and American hospital operator Heritage Valley Health System. The Cadbury's Chocolate Factory in
Hobart Hobart ( ) is the capital and most populous city of the island state of Tasmania, Australia. Located in Tasmania's south-east on the estuary of the River Derwent, it is the southernmost capital city in Australia. Despite containing nearly hal ...
, Tasmania, is the first company in Australia to be affected by Petya. On 28 June 2017, JNPT, India's largest container port, had reportedly been affected, with all operations coming to a standstill. Princeton Community Hospital in rural West Virginia will scrap and replace its entire computer network on its path to recovery. The business interruption to Maersk, the world's largest container ship and supply vessel operator, was estimated between $200m and $300m in lost revenues. The business impact on FedEx is estimated to be $400m in 2018, according to the company's 2019 annual report.
Jens Stoltenberg Jens Stoltenberg (; born 16 March 1959) is a Norwegian politician from the Labour Party. Since 2025, he has been the Minister of Finance in the Støre Cabinet. He has previously been the prime minister of Norway and secretary general of NATO. ...
,
NATO The North Atlantic Treaty Organization (NATO ; , OTAN), also called the North Atlantic Alliance, is an intergovernmental organization, intergovernmental Transnationalism, transnational military alliance of 32 Member states of NATO, member s ...
Secretary-General, pressed the alliance to strengthen its cyber defenses, saying that a cyberattack could trigger the Article 5 principle of collective defense. Mondelez International's insurance carrier, Zurich American Insurance Company, has refused to pay out a claim for cleaning up damage from a NotPetya infection, on the grounds that NotPetya is an "act of war" that is not covered by the policy. Mondelez sued Zurich American for $100 million in 2018; the suit was settled in 2022 with the terms of the settlement remaining confidential.


Reaction

Europol Europol, officially the European Union Agency for Law Enforcement Cooperation, is the law enforcement agency of the European Union (EU). Established in 1998, it is based in The Hague, Netherlands, and serves as the central hub for coordinating c ...
said it was aware of and urgently responding to reports of a cyber attack in member states of the
European Union The European Union (EU) is a supranational union, supranational political union, political and economic union of Member state of the European Union, member states that are Geography of the European Union, located primarily in Europe. The u ...
. The
United States Department of Homeland Security The United States Department of Homeland Security (DHS) is the U.S. United States federal executive departments, federal executive department responsible for public security, roughly comparable to the Interior minister, interior, Home Secretary ...
was involved and coordinating with its international and local partners. In a letter to the NSA, Democratic Congressman Ted Lieu asked the agency to collaborate more actively with technology companies to notify them of software vulnerabilities and help them prevent future attacks based on malware created by the NSA. On 15 February 2018, the Trump administration blamed Russia for the attack and warned that there would be "international consequences". The United Kingdom and the Australian government also issued similar statements. In October 2020 the DOJ named further GRU officers in an indictment. At the same time, the UK government blamed GRU's Sandworm also for attacks on the 2020 Summer Games.


Other notable low-level malware

* CIH (1998) *
Stuxnet Stuxnet is a Malware, malicious computer worm first uncovered on June 17, 2010, and thought to have been in development since at least 2005. Stuxnet targets supervisory control and data acquisition (SCADA) systems and is believed to be responsibl ...
(2010) * WannaCry (2017)


See also

* * * BlackEnergy * Domain controller (Windows) * EternalBlue * Mimikatz * Sandworm (hacker group) *
Server Message Block Server Message Block (SMB) is a communication protocol used to share files, printers, serial ports, and miscellaneous communications between nodes on a network. On Microsoft Windows, the SMB implementation consists of two vaguely named Windows ...
* Vulkan files leak


References


Further reading

* * {{Hacking in the 2010s, collapsed 2017 in computing 2017 in Ukraine Cyberattacks Cybercrime Cybercrime in India Hacking in the 2010s June 2017 crimes Ransomware India–Russia relations