Ransomware Group intelligence
NotPetya
InactiveTrack NotPetya with 2 published victims in a single intelligence view.
Overview
NotPetya is tracked by Breach House as a ransomware group with 2 published victims.
Denmark is currently the most targeted country in this dataset.
No leak location metadata is currently available for this group.
Leak Status Distribution
- Leaked 0 0.0%
- Pending 1 100.0%
- Deleted 0 0.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (0)
No known leak locations available for this group.
Top Activity Sectors (1)
Typical Attacks (14)
▼How NotPetya typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via NotPetya.
-
What they do: NotPetya can use valid credentials with PsExec or wmic to spread itself to remote systems.
What that means: Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1047 Windows Management Instrumentation Execution
What they do: NotPetya can use wmic to help propagate itself across a network.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
What they do: NotPetya creates a task to reboot the system one hour after infection.
What that means: Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code.
-
T1569.002 Service Execution Execution
What they do: NotPetya can use PsExec to help propagate itself across a network.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
T1036 Masquerading Stealth
What they do: NotPetya drops PsExec with the filename dllhost.dat.
What that means: Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.
-
T1218.011 Rundll32 Stealth
What they do: NotPetya uses rundll32.exe to install itself on remote systems when accessed via PsExec or wmic.
What that means: Adversaries may abuse rundll32.exe to proxy execution of malicious code.
-
T1685.005 Clear Windows Event Logs Defense Impairment
What they do: NotPetya uses wevtutil to clear the Windows event logs.
What that means: Adversaries may clear Windows Event Logs to hide the activity of an intrusion.
-
T1003.001 LSASS Memory Credential Access
What they do: NotPetya contains a modified version of Mimikatz to help gather credentials that are later used for lateral movement.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1083 File and Directory Discovery Discovery
What they do: NotPetya searches for files ending with dozens of different file extensions prior to encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1518.001 Security Software Discovery Discovery
What they do: NotPetya determines if specific antivirus programs are running on an infected host machine.
What that means: Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: NotPetya can use PsExec, which interacts with the ADMIN$ network share to execute commands on remote systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1210 Exploitation of Remote Services Lateral Movement
What they do: NotPetya can use two exploits in SMBv1, EternalBlue and EternalRomance, to spread itself to other remote systems on the network.
What that means: Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network.
-
T1486 Data Encrypted for Impact Impact
What they do: NotPetya encrypts user files and disk structures like the MBR with 2048-bit RSA.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1529 System Shutdown/Reboot Impact
What they do: NotPetya will reboot the system one hour after infection.
What that means: Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.
Crypto Wallets (3)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
1Ftixp78FjTWFi3ssJjBw5NqKf5ZPQjXBb |
bitcoin | $20,621 | 2 |
1Mz7153HMuxXTuR2R1t78mGSdzaAtNbBWX |
bitcoin | $12,536 | 115 |
13KBb1G7pkqcJcxpRHg387roBj2NX7Ufyf |
bitcoin | $1,275 | 6 |
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Victims (2)
Search, filter and paginate the victim timeline for NotPetya. Showing 1–2 of 2.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Maersk id31031 View details | Denmark | Transportation / Travel / Logistics | — | pending | |
|
Maersk is a global leader in the transportation and logistics sector, headquartered in Denmark. The company provides a range of services including container shipping, port operations, and logistics solutions to customers worldwide. Maersk operates in multiple countries and is a major player in the global supply chain. It was listed as a ransomware victim associated with NotPetya |
||||||
| Ransomware | Maersk id31031 View details | Denmark | Transportation / Travel / Logistics | — | pending | |
|
A.P. Moller-Maersk, the Danish shipping and logistics conglomerate, was hit by the NotPetya wiper malware, causing major disruption to its global container shipping operations. |
||||||