onlinesyscfg.research
utc
syscfg://research
home/research/notpetya
PublishedThreat History

NotPetya: The $10 Billion Cyberweapon Disguised as Ransomware

2026-08-09-21 min read
#notpetya#sandworm#gru#russia#ukraine#supply-chain#eternalblue#mimikatz#wiper#maersk

On June 27, 2017, companies around the world began receiving calls from IT departments with an unusual characteristic: the phones were not ringing in the offices being described. The computers were down. Not crashed - destroyed. Hard drives encrypted. Boot records overwritten. Networks dark. Within hours, the scope of the damage would become clear enough that several governments would eventually classify it as an act of war.

The malware was called NotPetya - named for its resemblance to an earlier ransomware called Petya, which it both resembled and fundamentally differed from. Petya was ransomware. NotPetya was a cyberweapon. The ransom note was a decoy. The decryption key was meaningless. The goal was destruction.

◈ interactive artifact
NotPetya Attack Simulation
Simulate the NotPetya attack: MEDoc supply chain infection, EternalBlue lateral movement, Mimikatz credential theft, MBR overwrite, and the fake ransom screen.

//The Supply Chain: MEDoc

NotPetya reached most of its victims through a software update. M.E.Doc is Ukrainian accounting software required by law for businesses operating in Ukraine to file their taxes. In a country where roughly 80% of businesses used the software, a compromised update to M.E.Doc was effectively a compromised update to the Ukrainian economy.

The attackers - later attributed to Sandworm, a unit of Russian military intelligence (GRU) - had compromised M.E.Doc's update infrastructure. They modified the legitimate update mechanism to deliver a backdoor alongside the real software update. When businesses downloaded the May 2017 update to stay compliant with Ukrainian tax filing requirements, they installed the backdoor. On June 27, the backdoor received a command to deploy the NotPetya payload.

This was a supply chain attack of a kind that security researchers had discussed theoretically but rarely seen executed at this scale. The victims had done nothing wrong. They had downloaded a legitimate software update from a legitimate vendor using legitimate authentication. The compromise happened upstream, at the vendor.

//Spreading: EternalBlue and Mimikatz

Once inside a network, NotPetya spread using two complementary mechanisms. The first was EternalBlue - the NSA exploit for SMBv1 that had been leaked by the Shadow Brokers two months earlier and used in WannaCry weeks before NotPetya. Despite the WannaCry outbreak having demonstrated the severity of the vulnerability, many organizations had not yet patched.

The second mechanism was credential theft using code derived from Mimikatz, a legitimate security tool that extracts Windows credentials from the LSASS process in memory. On a domain network, if NotPetya compromised a single machine and extracted credentials with domain-level privileges, it could use WMIC or PsExec to execute itself on every other machine it could reach using those credentials.

[WARNING]
This combination was particularly devastating. EternalBlue handled unpatched systems. Mimikatz handled patched systems where a domain admin had recently logged in. An organization that had patched every machine against EternalBlue was still vulnerable if NotPetya could extract an admin credential from any machine and use WMI to spread.

//The Payload: Overwriting the MBR

NotPetya's destructive payload worked in two stages. First, it encrypted the Master File Table (MFT) - the NTFS index that records where every file on the disk is located. Second, it overwrote the Master Boot Record with a custom bootloader displaying the fake ransom note.

The fake ransom note demanded $300 in Bitcoin to the address 1Mz7153HMuxXTuR2R1t78mGSdzaAtNbBWX. But the email address used for decryption key requests was shut down by the provider within hours of discovery. More fundamentally, the encryption key was generated randomly per machine and immediately discarded. There was no server to send it to. There was no decryption capability. The ransomware framing was misdirection.

The choice to disguise a wiper as ransomware was significant. Ransomware implies the possibility of recovery. Ransomware implies the attackers want money. A pure wiper attack would have been immediately recognized as an act of war. A ransomware attack with a dysfunctional payment mechanism was initially treated as sloppy criminal work rather than deliberate state-sponsored destruction.

//Maersk: 10 Days to Rebuild

Maersk, the world's largest shipping company, had an office in Ukraine that was connected to their global network. NotPetya entered through this connection and spread to every corner of Maersk's infrastructure in minutes. By the time the company's IT team understood what was happening, it was over.

The numbers Maersk later disclosed were staggering: 45,000 PCs destroyed. 4,000 servers destroyed. 2,500 applications dead. Every one of Maersk's 17 global container terminals was offline. The company was handling roughly 20% of global shipping at the time. With no computer systems, they could not accept new container loads or track existing ones. Ports ground to a halt.

Rebuilding Maersk's infrastructure took ten days. They had to fly engineers to Lagos, Nigeria, to retrieve a single working backup domain controller - reportedly the only surviving domain controller in their global network, saved by a power outage in the Lagos office at the moment of the attack. The Lagos DC was the seed from which the entire Active Directory was reconstructed.

[INFO]
Maersk later reported a total cost of $200-$300 million from NotPetya. Merck Pharmaceuticals: $870 million. FedEx's TNT subsidiary: $400 million. Mondelez International: $188 million. Reckitt Benckiser: $129 million. Total estimated global damages exceeded $10 billion, making NotPetya the most economically destructive cyberattack in history.

//Attribution to Russia

Sandworm, the GRU unit responsible for NotPetya, had a track record. They had previously attacked Ukraine's power grid in December 2015 using BlackEnergy - the first known cyberattack to cause a blackout, affecting 225,000 people. A second attack in December 2016 used Industroyer, a more sophisticated ICS-targeting malware.

The timing of NotPetya was significant. It launched on June 27, 2017 - Constitution Day in Ukraine, a national holiday. The primary initial victims were Ukrainian businesses. The M.E.Doc supply chain attack required specific knowledge of Ukrainian business software requirements. The broader global damage - Maersk, Merck, FedEx - was collateral damage from an attack primarily targeting Ukraine's economy.

Multiple governments formally attributed NotPetya to GRU's Sandworm unit: the US, UK, Canada, Australia, and New Zealand all issued coordinated attribution statements in February 2018. The UK's National Cyber Security Centre said the GRU was "almost certainly responsible." The US Department of Justice indicted six GRU officers for the attack in 2020.

//The Insurance Wars

NotPetya generated a significant legal battle over whether standard property and casualty insurance policies covered damages from nation-state cyberattacks. Many policies included "act of war" exclusions. Insurers attempted to invoke these exclusions to deny claims from companies that suffered NotPetya losses.

Mondelez International sued Zurich Insurance when Zurich denied a $100 million claim, citing the act of war exclusion and the US and UK attribution of NotPetya to Russia. The case settled in 2022. Merck won a $1.4 billion judgment against its insurers when the New Jersey Superior Court ruled that the act of war exclusion did not apply to state-sponsored cyber attacks on private companies. The cases drove a wholesale re-examination of cyber insurance policy language.

What NotPetya Taught Security Teams

The lessons from NotPetya have been rehearsed extensively in the years since: network segmentation would have contained the spread; the combination of EternalBlue and Mimikatz required both patching and credential hygiene to defeat; offline backup copies are meaningless if the only way to access them is the network that just got destroyed; and supply chain security is as important as perimeter security.

Most significantly: NotPetya demonstrated that nation-state cyberweapons can escape their intended targets and cause global collateral damage. The attack was aimed at Ukraine. The shipping company whose container operations it paralysed was Danish, headquartered in Copenhagen. Geopolitics is no longer confined to geographic borders when the weapon is software.