Skip to content

Hide Navigation Hide TOC

NotPetya (00c31914-bc0e-11e8-8241-3ff3b5e4671d)

Threat actors deploy a tool, called NotPetya, with the purpose of encrypting data on victims' machines and rendering it unusable. The malware was spread through tax software that companies and individuals require for filing taxes in Ukraine. Australia, Estonia, Denmark, Lithuania, Ukraine, the United Kingdom, and the United States issued statements attributing NotPetya to Russian state-sponsored actors. In June 2018, the United States sanctioned Russian organizations believed to have assisted the Russian state-sponsored actors with the operation.

Cluster A Galaxy A Cluster B Galaxy B Level
EternalPetya (6f736038-4f74-435b-8904-6870ee0e23ba) Malpedia NotPetya (00c31914-bc0e-11e8-8241-3ff3b5e4671d) Tool 1
Bad Rabbit (e8af6388-6575-4812-94a8-9df1567294c5) Ransomware NotPetya (00c31914-bc0e-11e8-8241-3ff3b5e4671d) Tool 1
EternalPetya (6f736038-4f74-435b-8904-6870ee0e23ba) Malpedia Bad Rabbit (e8af6388-6575-4812-94a8-9df1567294c5) Ransomware 2