logo

Petya Ransomware Outbreak

ID: d3f44008-cb25-56f6-8417-5a43b4d63f64

STIX ID: report--d3f44008-cb25-56f6-8417-5a43b4d63f64

Feed Name: Zscaler Security Research Blog

Threat Score
90/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ reports a widespread Petya-like ransomware outbreak delivered via a compromised MeDoc software update that encrypts infected systems' Master Boot Record and demands $300 in Bitcoin; the malware propagates laterally using SMB exploits (EternalBlue/MS17-010) and WMIC, impacting businesses across multiple countries. The report provides technical analysis of two DLL payloads (including a killswitch marker and scheduled reboot for payload activation), IOC hashes, sandbox detection signatures, and recommended mitigations (apply MS17-010/CVE-2017-0199 patches, disable SMBv1/WMIC, block ports 135/139/445).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.