On June 27, 2017, a software update for M.E.Doc - accounting software used by approximately 80% of Ukrainian businesses for tax filing - pushed malware to its users' machines. The malware, which security researchers named NotPetya, spread immediately across every network it touched using a combination of EternalBlue (the NSA-derived SMB exploit from WannaCry) and Mimikatz credential harvesting. It encrypted or destroyed every machine it reached, leaving no functional recovery path. Within hours, Ukrainian banks, government agencies, airports, hospitals, and utilities were dark. By that evening, NotPetya had spread globally to companies that had Ukrainian operations or network connections: Maersk, Merck, FedEx, Mondelez, Reckitt Benckiser. The total economic damage was approximately $10 billion - the most destructive cyberattack in history.
NotPetya was built to look like ransomware. It displayed a ransom demand and requested payment to a Bitcoin address. But there was no decryption functionality - the encryption keys were discarded, not stored for later ransom payment. The ransom demand was cover. NotPetya was a weapon, built by Russian military intelligence (GRU Unit 74455, Sandworm) and deployed against Ukraine. The global spread was, by most accounts, an unintended consequence of how aggressively NotPetya propagated through interconnected corporate networks.
The M.E.Doc Supply Chain Attack
M.E.Doc is a Ukrainian accounting software application required for electronic tax filing with Ukrainian authorities. Nearly every business operating in Ukraine used it. Sandworm compromised M.E.Doc's update infrastructure in the months before the June 27 attack, inserting a backdoor into the update server that allowed them to push malicious updates alongside legitimate software updates. When M.E.Doc pushed a routine software update on June 27, the malicious component downloaded and executed NotPetya on every machine running M.E.Doc.
The supply chain attack vector was deliberate and precise. Targeting M.E.Doc was targeting the Ukrainian business infrastructure directly - every organization that filed taxes electronically in Ukraine was a potential victim. The initial footprint was immediately enormous: tens of thousands of Ukrainian machines received the malware simultaneously through what appeared to be a legitimate software update from a trusted source.
EternalBlue Plus Mimikatz: The Propagation Engine
WannaCry, which had emerged six weeks before NotPetya, used only EternalBlue for propagation and was stopped by a kill switch domain. NotPetya was built differently. It used EternalBlue to spread to unpatched Windows machines via SMB, but it also used a more powerful technique: it ran Mimikatz to extract credentials from Windows memory (from the LSASS process), harvested network credentials stored in Windows credential manager, and used those credentials with Windows WMIC and PsExec to authenticate to other machines on the same network and install itself - machines that were fully patched and would have been immune to EternalBlue alone.
The credential harvesting technique meant that in a domain environment - a standard enterprise Active Directory network - NotPetya could spread to every machine that shared credentials with any machine it had already compromised. A single domain administrator who had logged into an infected machine had their credentials harvested, and NotPetya then used those admin credentials to authenticate to every other machine in the domain. In many corporate environments, this meant complete lateral compromise from a single initial foothold.
There was no command-and-control. NotPetya did not phone home, accept operator instructions, or maintain persistence. It was purely destructive: it encrypted the MBR, encrypted file table entries, and overwrote data, then forced a restart. The machine displayed a fake "CHKDSK" repair screen during the encryption process, disguising what was happening. On completion, it was inoperable and unrecoverable without a full rebuild.
The Global Spread
NotPetya escaped Ukraine through interconnected corporate networks. Companies with Ukrainian operations - offices, subsidiaries, suppliers, customers - that had network connections to Ukrainian systems found NotPetya spreading across those connections into their global infrastructure. The attack predated the era of fully segmented zero-trust architectures; most multinational corporations in 2017 maintained relatively open network connections between geographically distributed offices.
Maersk, the world's largest container shipping company, lost all 45,000 of its networked PCs and 4,000 servers. They had to rebuild their entire global IT infrastructure from scratch, restoring from backups and reinstalling software across offices in 130 countries. The full recovery took approximately 10 days of round-the-clock work. Maersk later reported total losses of $200-300 million. The company's chairman described the incident as a "force of nature" equivalent to natural disasters.
Merck, the pharmaceutical company, had manufacturing systems impacted and was unable to fill certain orders. FedEx's TNT subsidiary lost months of productivity and hundreds of millions of dollars. Reckitt Benckiser (consumer goods), Mondelez (food manufacturing), and dozens of other multinationals suffered significant damage. The total economic impact - across Ukrainian and global victims - reached approximately $10 billion by the most widely cited estimates.
Ukraine as the Target and the Lab
NotPetya was the third major Russian cyberattack against Ukrainian infrastructure in two years. The December 2015 power grid attack (BlackEnergy/KillDisk) had turned off lights for 230,000 Ukrainians for six hours. The December 2016 power grid attack (Industroyer) hit Kiev's transmission substation and cut power for about an hour. NotPetya in June 2017 caused the most widespread economic damage of any cyberattack ever. All three were Sandworm operations.
Ukraine's experience as a target of Russian cyber operations beginning in 2014 (with the outbreak of the Russia-Ukraine conflict over Crimea) made it the world's most active laboratory for state-sponsored cyberattacks. The techniques developed and refined against Ukrainian targets - wiper malware, supply chain compromise, grid attacks - were later deployed globally. WannaCry used EternalBlue that had been battle-tested in Eastern Europe. NotPetya brought both that experience and Sandworm's ICS attack capabilities to bear on a civilian economy.