logo

Petya starts with Ukraine and then goes global

ID: e7be1af2-5647-5003-8e27-fc09045e504a

STIX ID: report--e7be1af2-5647-5003-8e27-fc09045e504a

Feed Name: Group-IB Blog

Threat Score
90/100

Date Published: 2017-06-27

Date Updated: 2026-04-27

...
...

A coordinated Petya ransomware outbreak on June 27 leveraged a compromised update of Ukrainian accounting software (MeDoc) to infect roughly 80 organizations—primarily in Ukraine—and spread using exploits (CVE-2017-0199, EternalBlue/MS17-010) plus legitimate tools (PsExec, WMI); the malware encrypts files, overwrites MBR/MFT, displays ransom demands, and impacted banks, state enterprises, telecoms and infrastructure. The report includes malware analysis, a kill-switch description, compilation timestamps, victim lists, and detailed mitigation recommendations (patching, credential hygiene, backups, SMBv1 disablement).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.