Ransomware Group intelligence
NotPetya
InactiveTrack NotPetya with 2 published victims in a single intelligence view.
Overview
NotPetya is tracked by Dark Eye as a ransomware group with 2 published victims.
Denmark is currently the most targeted country in this dataset.
No leak location metadata is currently available for this group.
Leak Status Distribution
No leak-status data available yet.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (0)
No known leak locations available for this group.
Top Activity Sectors (1)
Typical Attacks (14)
▼How NotPetya typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via NotPetya.
-
What they do: NotPetya can use valid credentials with PsExec or wmic to spread itself to remote systems.
What that means: Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1047 Windows Management Instrumentation Execution
What they do: NotPetya can use wmic to help propagate itself across a network.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
What they do: NotPetya creates a task to reboot the system one hour after infection.
What that means: Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code.
-
T1569.002 Service Execution Execution
What they do: NotPetya can use PsExec to help propagate itself across a network.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
T1036 Masquerading Stealth
What they do: NotPetya drops PsExec with the filename dllhost.dat.
What that means: Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.
-
T1218.011 Rundll32 Stealth
What they do: NotPetya uses rundll32.exe to install itself on remote systems when accessed via PsExec or wmic.
What that means: Adversaries may abuse rundll32.exe to proxy execution of malicious code.
-
T1685.005 Clear Windows Event Logs Defense Impairment
What they do: NotPetya uses wevtutil to clear the Windows event logs.
What that means: Adversaries may clear Windows Event Logs to hide the activity of an intrusion.
-
T1003.001 LSASS Memory Credential Access
What they do: NotPetya contains a modified version of Mimikatz to help gather credentials that are later used for lateral movement.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1083 File and Directory Discovery Discovery
What they do: NotPetya searches for files ending with dozens of different file extensions prior to encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1518.001 Security Software Discovery Discovery
What they do: NotPetya determines if specific antivirus programs are running on an infected host machine.
What that means: Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: NotPetya can use PsExec, which interacts with the ADMIN$ network share to execute commands on remote systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1210 Exploitation of Remote Services Lateral Movement
What they do: NotPetya can use two exploits in SMBv1, EternalBlue and EternalRomance, to spread itself to other remote systems on the network.
What that means: Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network.
-
T1486 Data Encrypted for Impact Impact
What they do: NotPetya encrypts user files and disk structures like the MBR with 2048-bit RSA.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1529 System Shutdown/Reboot Impact
What they do: NotPetya will reboot the system one hour after infection.
What that means: Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.
Crypto Wallets (3)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
1Ftixp78FjTWFi3ssJjBw5NqKf5ZPQjXBb |
bitcoin | $20,621 | 2 |
1Mz7153HMuxXTuR2R1t78mGSdzaAtNbBWX |
bitcoin | $12,536 | 115 |
13KBb1G7pkqcJcxpRHg387roBj2NX7Ufyf |
bitcoin | $1,275 | 6 |
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Victims (2)
Search, filter and paginate the victim timeline for NotPetya. Showing 1–2 of 2.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Maersk id31031 View details | Denmark | Transportation / Travel / Logistics | — | — | |
|
Maersk is a global leader in the transportation and logistics sector, headquartered in Denmark. The company provides a range of services including container shipping, port operations, and logistics solutions to customers worldwide. Maersk operates in multiple countries and is a major player in the global supply chain. It was listed as a ransomware victim associated with NotPetya |
||||||
| Ransomware | Maersk id31031 View details | Denmark | Transportation / Travel / Logistics | — | — | |
|
A.P. Moller-Maersk, the Danish shipping and logistics conglomerate, was hit by the NotPetya wiper malware, causing major disruption to its global container shipping operations. |
||||||