NotPetya

S0368

Malware.View on attack.mitre.org

About this malware

NotPetya is malware that was used by Sandworm Team in a worldwide attack starting on June 27, 2017. While NotPetya appears as a form of ransomware, its main purpose was to destroy data and disk structures on compromised systems; the attackers never intended to make the encrypted data recoverable. As such, NotPetya may be more appropriately thought of as a form of wiper malware. NotPetya contains worm-like features to spread itself across a computer network using the SMBv1 exploits EternalBlue and EternalRomance.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1003.001
LSASS Memory

NotPetya contains a modified version of Mimikatz to help gather credentials that are later used for lateral movement.

T1021.002
SMB/Windows Admin Shares

NotPetya can use PsExec, which interacts with the ADMIN$ network share to execute commands on remote systems.

T1036
Masquerading

NotPetya drops PsExec with the filename dllhost.dat.

T1047
Windows Management Instrumentation

NotPetya can use wmic to help propagate itself across a network.

T1053.005
Scheduled Task

NotPetya creates a task to reboot the system one hour after infection.

T1078.003
Local Accounts

NotPetya can use valid credentials with PsExec or wmic to spread itself to remote systems.

T1083
File and Directory Discovery

NotPetya searches for files ending with dozens of different file extensions prior to encryption.

T1210
Exploitation of Remote Services

NotPetya can use two exploits in SMBv1, EternalBlue and EternalRomance, to spread itself to other remote systems on the network.

T1218.011
Rundll32

NotPetya uses rundll32.exe to install itself on remote systems when accessed via PsExec or wmic.

T1486
Data Encrypted for Impact

NotPetya encrypts user files and disk structures like the MBR with 2048-bit RSA.

T1518.001
Security Software Discovery

NotPetya determines if specific antivirus programs are running on an infected host machine.

T1529
System Shutdown/Reboot

NotPetya will reboot the system one hour after infection.

T1569.002
Service Execution

NotPetya can use PsExec to help propagate itself across a network.

T1685.005
Clear Windows Event Logs

NotPetya uses wevtutil to clear the Windows event logs.

Groups that use it1

Campaigns0

None recorded.

References4

  1. ESET Telebots June 2017 Open source
    Cherepanov, A.. (2017, June 30). TeleBots are back: Supply chain attacks against Ukraine. Retrieved June 11, 2020.
  2. Talos Nyetya June 2017 Open source
    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.
  3. US District Court Indictment GRU Unit 74455 October 2020 Open source
    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.
  4. US-CERT NotPetya 2017 Open source
    US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.