Comparing EternalPetya and BadRabbit
ID: 90f2e638-f18e-564d-8e05-a1054e25156c
STIX ID: report--90f2e638-f18e-564d-8e05-a1054e25156c
Feed Name: Blaze's Security Blog
This post presents a comparison of the 2017 EternalPetya (ExPetr/NotPetya) and BadRabbit ransomware outbreaks, proposing they are closely related or possibly developed by the same actors, and discussing BadRabbit’s potential purpose as a smokescreen for disruption and extortion. It provides practical guidance on prevention and recovery—emphasizing that decryption is unlikely without the criminals’ key—and details steps such as safe-mode boot, backups, MBR restoration, and file recovery using Shadow Volume Copies or tools like Shadow Explorer, PhotoRec, and Recuva.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
