THREAT DOSSIER / 02

2017 · Destructive disk wiper disguised as ransomware

NotPetya

Entered through a compromised M.E.Doc update, then moved through networks using SMB and credentials, producing worldwide disruption.

01

Entry and propagation

A compromised software supply chain followed by internal propagation through SMB, administrative tools and stolen credentials.

02

Targets

Ukrainian organizations first, then global transport, health, pharmaceutical and commercial firms.

03

Impact

Irrecoverable encryption and global losses in the billions; three documented victims alone lost nearly one billion dollars.

04

Defense

Control supplier risk, isolate administration tools, reduce privileges, segment networks and keep offline backups.