logo

Liveblog: Huge Petya ransomware wave

ID: a5576d42-4852-55a8-b09c-1dbdb140dca4

STIX ID: report--a5576d42-4852-55a8-b09c-1dbdb140dca4

Feed Name: Fox-IT blog

Threat Score
85/100

Date Published: 2017-06-27

Date Updated: 2026-05-05

...
...

A June 27, 2017 intelligence report describes a new Petya ransomware variant that spread from Ukraine—likely via compromised Me-Doc auto-update servers—encrypting disks, rebooting victims to a ransom screen, and propagating across internal networks using EternalBlue and tools like PSEXEC/WMI; the report details infection behavior, mitigation steps (patch MS17-010, disable SMBv1, limit admin accounts, backups) and includes a Snort detection rule.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.