logo

NotPetya pulls BadRabbit out of the hat

ID: 150ed20d-a8ee-5246-91b7-c3c67e358bd3

STIX ID: report--150ed20d-a8ee-5246-91b7-c3c67e358bd3

Feed Name: Group-IB Blog

Threat Score
75/100

Date Published: 2017-10-26

Date Updated: 2026-04-27

...
...

This report analyzes the October 2017 BadRabbit ransomware campaign that propagated via drive-by downloads from compromised news and other websites in Ukraine, Russia and elsewhere. The malware drops infpub.dat, installs a disk driver and MBR encryptor, uses Mimikatz to harvest credentials, generates a unique AES/RSA-based key per machine and unique Bitcoin wallets, deletes logs, and schedules shutdown tasks; the report links code similarities to NotPetya, lists IOCs (domains, SHA256/MD5 hashes, compilation dates) and discusses likely attribution and infrastructure details.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.