NotPetya

lore

security

A 2017 destructive malware outbreak disguised as ransomware.

NotPetya spread using the same EternalBlue exploit as WannaCry but was designed to destroy data rather than collect ransom. It caused billions in damage to global companies and is widely attributed to a nation-state.

NotPetya presented as ransomware and was not. It encrypted systems and displayed a ransom demand, but the encryption was constructed so recovery was impossible even with payment, which means the ransom was camouflage for destruction.

Its spread was through a compromised update mechanism for Ukrainian accounting software, which is a supply chain attack in its purest form: the malicious code arrived signed, through the trusted channel, from the vendor. It then propagated laterally using stolen credentials and a leaked exploit, which meant organizations with a single Ukrainian subsidiary lost their entire global network within hours.

The damage is estimated in the billions and is the most expensive cyberattack on record, and the aftermath produced a legal question that mattered more than the malware. Insurers denied claims under war exclusions on the basis of state attribution, and the resulting litigation reshaped how cyber insurance is written. NotPetya is therefore the case that established that a destructive attack can cross from a security incident into an uninsurable act, which is a category of risk most organizations had never considered.

Also known as: NotPetya, ExPetr

Sources

  • NotPetya (2017)

All glossary entries