logo

New Petya Ransomware variant hits Russia & Ukraine

ID: 9718b4f3-8f22-5b12-b4e3-173bdcb68460

STIX ID: report--9718b4f3-8f22-5b12-b4e3-173bdcb68460

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ analyzed the Bad Rabbit ransomware campaign (Oct 2017), which spread via compromised news and media sites serving a fake Adobe Flash installer. The installer drops a malicious DLL (infpub.dat) that encrypts files using AES (appending a Unicode "encrypted" marker), performs SMB-based lateral movement using embedded credential lists to brute-force shares, and displays a ransom note with Tor payment instructions; MD5 indicators and compromised intermediate domains are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.