NotPetya — Malware Profile
NotPetya is malware that was used by Sandworm Team in a worldwide attack starting on June 27, 2017. While NotPetya appears as a form of ransomware, its main purpose was to destroy data and disk structures on compromised systems; the attackers never intended to make the encrypted data recoverable. As such, NotPetya may be more appropriately thought of as a form of wiper malware. NotPetya contains worm-like features to spread itself across a computer network using the SMBv1 exploits EternalBlue and EternalRomance.
MITRE ATT&CK techniques (14)
- T1003.001 LSASS Memory
- T1021.002 SMB/Windows Admin Shares
- T1036 Masquerading
- T1047 Windows Management Instrumentation
- T1053.005 Scheduled Task
- T1078.003 Local Accounts
- T1083 File and Directory Discovery
- T1210 Exploitation of Remote Services
- T1218.011 Rundll32
- T1486 Data Encrypted for Impact
- T1518.001 Security Software Discovery
- T1529 System Shutdown/Reboot
- T1569.002 Service Execution
- T1685.005 Clear Windows Event Logs