logo

FAQ about PETYA/GOLDENEYE/PETR outbreak

ID: 927db743-f680-5741-bbc6-d8f6de042360

STIX ID: report--927db743-f680-5741-bbc6-d8f6de042360

Feed Name: Fox-IT blog

Threat Score
80/100

Date Published: 2017-06-28

Date Updated: 2026-04-27

...
...

**Executive summary:** This FAQ describes the Petya ransomware outbreak that began with a malicious update to Ukrainian accounting software M.E.Doc and spread laterally using leaked NSA exploits (EternalBlue/EternalRomance), credential harvesting and reuse, and legitimate admin tools (PsExec, WMI), resulting in file- and disk-level encryption that renders systems inoperable; it provides detection and mitigation guidance (MS17-010/KB2871997 patches, network port scans, credential inventory), notes a local "antidote" (placing the perfc/perfc.dat file), and warns that ransom payments are ineffective because the payment email was blocked.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.