On June 27, 2017, a software update pushed through M.E.Doc - Ukrainian accounting software used by approximately 80% of Ukrainian businesses for tax filings - began encrypting hard drives. The malware called itself "Petya" but was not Petya. Security researchers quickly named it "NotPetya" to distinguish it from the ransomware it superficially resembled. NotPetya was not ransomware. It was a wiper disguised as ransomware - a cyberweapon designed to destroy data without any possibility of recovery. The ransom demand displayed on encrypted screens was theater. There was no working decryption mechanism. There never was.

What followed in the next 24 hours was the most destructive cyberattack in history by direct financial impact. NotPetya spread from Ukraine using EternalBlue (the same NSA exploit used by WannaCry six weeks earlier) combined with a credential-stealing module that extracted Windows account hashes from memory and used them to propagate laterally across corporate networks without any user interaction. The malware hit shipping giant Maersk, pharmaceutical company Merck, FedEx subsidiary TNT Express, construction company Saint-Gobain, food company Mondelez, advertising holding company WPP, and thousands of other companies. Total losses exceeded $10 billion.

The M.E.Doc Supply Chain Attack

M.E.Doc was the entry point. The software had an auto-update feature; attackers (later attributed to Sandworm, a Russian GRU Unit 74455 operation) had compromised M.E.Doc's update infrastructure months before the June 27 deployment. The backdoor inserted into M.E.Doc's update system gave Sandworm persistent access to any machine running the software and the ability to push arbitrary code as a software update.

When Sandworm pushed NotPetya through the M.E.Doc update on June 27, every machine running M.E.Doc that accepted the update received the malware simultaneously. Because M.E.Doc was essentially mandatory for Ukrainian businesses conducting tax compliance, the initial infection was enormous: Ukrainian government ministries, banks, airports, the Kyiv metro system, state power company Ukrenergo, and thousands of private businesses all received the update and began encrypting simultaneously.

The intent was clearly to cause maximum disruption in Ukraine. But NotPetya didn't stay in Ukraine. The propagation mechanisms - EternalBlue for unpatched SMBv1 systems, and credential-based lateral movement using extracted NTLM hashes - spread the malware to any machine reachable from an infected network, regardless of geographic location. Companies with even modest connectivity to Ukrainian offices or subsidiaries found the malware spreading through their global networks. This was the mechanism by which NotPetya became a global incident rather than a Ukraine-specific attack.

[TECHNICAL NOTE]
NotPetya's propagation combined three techniques. First: EternalBlue (MS17-010), which exploited a remote code execution vulnerability in Windows SMBv1 to spread without credentials or user interaction to any reachable unpatched machine. Second: credential harvesting using a Mimikatz-derived module that extracted NTLM hashes and plaintext passwords from LSASS memory. Third: these credentials were used with Windows administrative tools (PsExec, WMIC) to execute the malware on remote machines where the stolen credentials were valid - typically via admin shares. The combination meant that even networks fully patched against EternalBlue could be hit via the credential-based propagation if any machine with valid admin credentials was compromised first. The overwrite process targeted the Master Boot Record (MBR) and Master File Table (MFT) of NTFS volumes - overwriting the MBR prevents the machine from booting; overwriting the MFT destroys the filesystem's ability to locate files. Neither operation is reversible. The displayed ransom message was a decoy; even if victims paid, there was no mechanism to receive a key.

Maersk: Reinstalling an Empire in 10 Days

A.P. Moller-Maersk is the world's largest container shipping company, handling approximately 20% of global ocean container freight. NotPetya reached Maersk through its Ukrainian operations. The malware spread across Maersk's global network within minutes, taking down approximately 45,000 PCs and 4,000 servers across 130 countries. Maersk's port operations worldwide stopped. Ships at sea could still sail, but the logistics and booking systems that coordinated container movements were gone.

Maersk's recovery became one of the most documented disaster recovery operations in corporate history. The company had to reinstall its entire IT infrastructure from scratch. They needed to restore their Active Directory. By a near-miraculous accident of timing, one AD domain controller in Ghana had been offline during the attack because of a local power outage - and came back online after NotPetya had finished spreading. That single surviving domain controller, in Ghana, contained the directory information needed to rebuild Maersk's global AD forest. The company flew a team to Accra to recover it.

The reinstallation required 45,000 new PCs, 4,000 servers, and 2,500 applications in approximately 10 days - with Maersk employees working around the clock and hundreds of IT staff volunteering to participate. Maersk's CEO later said the Ghana domain controller "was a savior." The total cost to Maersk was approximately $300 million. The incident triggered a comprehensive rebuild of Maersk's IT security architecture, including network segmentation, endpoint security, and backup systems that hadn't existed before.

[WARNING]
NotPetya's $10 billion+ total cost set an important legal and insurance precedent. Many of the affected companies had cyber insurance. Mondelez International, which lost approximately $100 million to NotPetya, filed a claim against their insurer Zurich. Zurich denied the claim, citing a "war exclusion" - standard insurance policy language that excludes losses caused by acts of war. The US, UK, and EU governments had attributed NotPetya to Russia's GRU by early 2018, and Zurich argued that a nation-state cyberattack constituted an "act of war." Mondelez sued. The case settled in 2022, but the underlying "war exclusion" question remained deeply relevant: as nation-state cyberattacks become more common and more destructive, the insurance industry's willingness to cover them is uncertain. Lloyd's of London subsequently issued guidance requiring explicit cyber war exclusions in standalone cyber policies, shifting the burden to insureds to explicitly purchase war coverage or accept that nation-state attacks may not be covered.

Attribution and Geopolitical Context

NotPetya was deployed on June 27, 2017 - the day before Ukraine's Constitution Day, a national holiday. The timing, the M.E.Doc delivery mechanism, and the primary targeting of Ukrainian infrastructure all pointed to Russian state involvement from early in the investigation. In February 2018, the US, UK, Australian, Canadian, and other governments formally attributed NotPetya to Sandworm, identifying it as an operation by the GRU's Main Centre for Special Technologies (GTsST), Unit 74455.

The same group - Sandworm - was responsible for the 2015 and 2016 Ukraine power grid attacks, the Olympic Destroyer malware at the 2018 Pyeongchang Olympics, and the Industroyer2 attack on Ukraine's power grid in April 2022. The pattern represents Russia's ongoing use of destructive cyber operations as an instrument of its campaign against Ukraine, with collateral damage to global companies treated as acceptable or even desired.

In October 2020, the DOJ indicted six Russian GRU officers in connection with NotPetya, the 2018 Olympic Destroyer attack, and other operations. The individuals named - Yuriy Andrienko, Sergei Detistov, Pavel Frolov, Anatoliy Kovalev, Artem Ochichenko, and Petr Pliskin - were alleged to be members of Unit 74455 operating under GRU Center 16 and Center 74455. No extraditions were expected; the indictments were primarily a public attribution and naming action.

[IOC]
NotPetya technical indicators: initial dropper arrived via M.E.Doc update or as "perfc.dat" in %WINDIR% (also distributed as "myguy.xls.hta" or via EternalBlue directly). The malware checked for the existence of C:\Windows\perfc - if present, did not execute (this became a "vaccine" that could prevent infection on individual machines, though not stop network spread). NotPetya overwrote the first sectors of physical drives to destroy the MBR, then overwrote the MFT. Propagation used TCP 139, 445 (SMB via EternalBlue), and admin shares with harvested credentials. The fake ransom note displayed "Oops, your important files are encrypted" with a Bitcoin address and an email ([email protected] - blocked by Posteo almost immediately). No working decryption existed. If you have NotPetya-encrypted drives, they cannot be recovered without backups. Sandworm attribution: US Cyber Command, NSA, FBI, CISA joint advisory; UK NCSC; Australian Signals Directorate; New Zealand GCSB. GRU Unit 74455 building identifier: 22 Kirova Street, Khimki, Moscow Oblast.