EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/cyberattack/notpetya-2017
236/430

File EL-0195CriticalResolvedCyberattack / Destructive Malware / Sabotage

NotPetya

Also filed as Petya · Wiper Malware · Sandworm Attack

NotPetya was a highly destructive piece of malware, initially disguised as ransomware but functioning primarily as a wiper. It was launched against Ukraine on the eve of its Constitution Day, causing massive systemic disruption. The attack spread through compromised Ukrainian software, quickly escalating to affect global multinational corporations.

  • #ransomware
  • #wiper
  • #gru
  • #ukraine
  • #maersk
  • #supply-chain-attack
Notoriety9/10
Event
27 Jun 2017
Disclosed
27 Jun 2017
Target
Ukraine
Actor
Sandworm
Scale
N/A (Destructive)
Status
Resolved

01Summary

NotPetya was deployed by state-sponsored actors, widely attributed to Russia's GRU, targeting Ukraine's critical infrastructure. The malware exploited a supply chain vulnerability via compromised Ukrainian accounting software (MeDoc), allowing it to spread rapidly and infect systems across the country. While it displayed ransomware characteristics, its primary function was data destruction, rendering systems unusable and irreversible. The attack quickly transcended national borders, crippling global logistics and corporate operations. Major victims included Maersk, which halted global shipping, and Merck, which suffered significant financial losses. The incident demonstrated a new level of state-sponsored cyber warfare, causing estimated damages exceeding $10 billion.

02Background

The attack occurred on June 27, 2017, a date of high geopolitical tension between Russia and Ukraine. The timing suggests a deliberate act of sabotage intended to destabilize the Ukrainian government and economy. The use of a seemingly benign, localized software update as the initial vector allowed the malware to bypass typical perimeter defenses.

03Key revelations

  1. 01The malware's primary function was data destruction (wiper), not merely extortion.
  2. 02The attack demonstrated a sophisticated, state-level capability to cripple global supply chains.
  3. 03The initial vector was a localized, trusted software update, highlighting supply chain risk.

04Technical analysis

NotPetya utilized a combination of ransomware and wiper functionality. It spread via the EternalBlue exploit (MS17-010), a vulnerability previously used in WannaCry, and leveraged network shares and compromised credentials for lateral movement. The malware was designed to overwrite the Master Boot Record (MBR) and critical system files, ensuring data was permanently lost, regardless of backups.

Attack vector
Supply Chain Compromise (via compromised MeDoc accounting software update)
Attack method
Wiper/Ransomware Hybrid
Initial access
Compromised Software Update
Lateral movement
Network Shares / Exploitation (EternalBlue)
Persistence
Registry Modification / MBR Overwrite
Exfiltration
None (Wiper function)
Tool / malware
NotPetya
Malware family
Petya/NotPetya
Malware type
Wiper/Ransomware

Vulnerabilities exploited

  • MS17-010 (EternalBlue)

MITRE ATT&CK techniques

  • T1566.001
  • T1021.001
  • T1078

05Threat actor

Sandworm is a highly sophisticated, state-sponsored threat group attributed to Russia's GRU. They are known for developing and deploying destructive, high-impact malware, often targeting critical infrastructure and government systems to achieve geopolitical objectives.

Aliases

  • GRU Unit 74455
  • Fancy Bear

APT designations

  • APT28
  • Fancy Bear

MITRE groups

  • T1486

Attribution sources

  • Microsoft
  • Reuters
  • The Wall Street Journal
  • Mandiant

06Victims and impact

Additional victims

  • Maersk
  • Merck
  • Global Shipping Industry

Countries affected

  • Ukraine
  • Denmark
  • United States
  • Global

07Data exposed

Data types

  • Operating System Files
  • System Data
  • Corporate Records

Notable documents

  • MeDoc Update Package

08Financial damage

Estimated total global damage, cited by multiple sources, exceeding $10 billion.

09Timeline

  1. 2017-06-27NotPetya is launched, targeting Ukrainian infrastructure.
  2. 2017-06-28Malware spreads globally, affecting multinational corporations like Maersk and Merck.
  3. 2017-07-20Most major affected systems begin to recover and stabilize.

10Reaction and fallout

Public reaction

The global public reaction was characterized by shock and fear, as the attack demonstrated the vulnerability of interconnected global systems. Governments and corporations immediately began reviewing their cyber resilience and incident response plans.

Political impact

The attack significantly heightened international tensions, leading to increased public and private sector scrutiny of Russian cyber capabilities. It fueled calls for stronger international cyber norms and defensive alliances.

Geopolitical consequences

The incident was widely cited as a major escalation in the cyber conflict between Russia and the West, contributing to the narrative of Russia's use of cyber warfare as a tool of foreign policy.

11Legal

No specific international legal action was taken, but the incident contributed to the development of national cyber defense strategies and increased diplomatic pressure on Russia.

Civil lawsuits

  • Maersk vs. Unknown State Actor (Cyber Damages)

12Aftermath

Policy changes

  • Increased focus on supply chain security and third-party vendor risk management.
  • Adoption of mandatory cyber resilience standards in critical infrastructure sectors.

Regulatory changes

  • Strengthening of national cyber defense frameworks (e.g., NIS Directive updates in EU).

Security improvements

  • Mandatory network segmentation and air-gapping of critical operational technology (OT) systems.
  • Enhanced patch management and vulnerability scanning across global networks.

13Significance and legacy

Significance

NotPetya is historically significant because it marked a clear transition from cyber espionage (data theft) to cyber sabotage (data destruction) on a global scale. It demonstrated that state-level actors could inflict massive, quantifiable economic damage without necessarily achieving their stated intelligence goals.

Legacy

The attack permanently changed the risk assessment model for critical infrastructure, forcing governments and industries to treat cyberattacks as a physical threat. It accelerated the global push for cyber resilience and international cooperation on cyber norms.

14Disclosure and media

Authentication
Technical Analysis / Forensic Examination

Media partners

  • Reuters
  • The Wall Street Journal

Publishing organisations

  • Mandiant
  • Microsoft

15Related files

Related events

Went on to inspire

16Field notes

  1. 01The malware was initially disguised as a legitimate update for MeDoc, a popular Ukrainian accounting program.
  2. 02The attack was so destructive that it forced the world's largest shipping company, Maersk, to halt operations and rebuild thousands of servers.

17Resolution

The global response involved massive IT overhauls, system re-imaging, and the implementation of stricter network security protocols across affected industries.

18Sources

Official documents

  • Microsoft Threat Intelligence Reports (2017)

References

  1. [1]Mandiant Threat Intelligence Report: NotPetya
  2. [2]Reuters Coverage of Maersk Outage
Fact sheetEL-0195

Dates

Event
27 Jun 2017
Started
27 Jun 2017
Ended
30 Jun 2017
Duration
23 days
Discovered
27 Jun 2017
Disclosed
27 Jun 2017
Resolved
20 Jul 2017
Ongoing
No

Target

Organisation
Ukraine
Type
Government
Sector
Government/Critical Infrastructure
Country
Ukraine
Gov. level
Federal

Actor

Name
Sandworm
Type
Nation-State Actor
Nationality
Russian
Nation-state
Russia
Affiliation
GRU (Main Intelligence Directorate)
Motivation
Geopolitical sabotage and disruption of Ukrainian infrastructure and economy.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
N/A (Destructive)
Sensitivity
Mixed
Published
No

Money

Damage
$10,000,000,000

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.