NotPetya Ransomware 5

Overview

NotPetya is a destructive malware disguised as ransomware. It caused an estimated $10 billion in damages worldwide.

Known Aliases

  • Petya.A
  • ExPetr
  • GoldenEye

Associated Malware or Tools

  • EternalBlue (MS17-010 exploit)
  • Mimikatz (credential harvesting)
  • PsExec (lateral movement)

Techniques and TTPs (Mitre ATT&CK Mapping)

  • T1210 - Exploitation of Remote Services
  • T1003 - OS Credential Dumping
  • T1486 - Data Encrypted for Impact

Detection and Prevention

Apply all security patches promptly. Segment networks to limit lateral movement. Deploy EDR solutions.