logo

Comparing EternalPetya and BadRabbit

ID: 90f2e638-f18e-564d-8e05-a1054e25156c

STIX ID: report--90f2e638-f18e-564d-8e05-a1054e25156c

Feed Name: Blaze's Security Blog

Threat Score
70/100

Date Published: 2017-10-25

Date Updated: 2026-04-19

Author: Bart

...
...

This post presents a comparison of the 2017 EternalPetya (ExPetr/NotPetya) and BadRabbit ransomware outbreaks, proposing they are closely related or possibly developed by the same actors, and discussing BadRabbit’s potential purpose as a smokescreen for disruption and extortion. It provides practical guidance on prevention and recovery—emphasizing that decryption is unlikely without the criminals’ key—and details steps such as safe-mode boot, backups, MBR restoration, and file recovery using Shadow Volume Copies or tools like Shadow Explorer, PhotoRec, and Recuva.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.