Skip to main content

Operator dossier

NotPetya is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 1 public victims claimed by this operator between January 1, 2017. NotPetya is a destructive malware campaign — widely assessed by the intelligence community and leading cybersecurity researchers not as a traditional ransomware operation but as a cyberweapon disguised as ransomware — that emerged in June 2017 and caused catastrophic, indiscriminate damage to global organizations, with financial destruction rather than ransom collection assessed as a secondary concern to its primary destructive intent. Attributed with high confidence by the United States, United Kingdom, European Union, and Australia to Sandworm Team, a threat actor operating under Russia's GRU military intelligence directorate, NotPetya is not a Ransomware-as-a-Service operation but rather a state-sponsored destructive tool, with links to earlier Sandworm campaigns including the BlackEnergy and Industroyer attacks targeting Ukrainian critical infrastructure. NotPetya gained initial access primarily through the poisoned Ukrainian accounting software MeDoc, leveraging a trojanized software update mechanism as a supply chain attack vector, subsequently propagating laterally at extraordinary speed using the EternalBlue and EternalRomance NSA-derived exploits alongside the Mimikatz credential harvesting tool, with no genuine decryption capability ever offered — rendering it a wiper rather than functional ransomware. The campaign struck Danish shipping giant Maersk, pharmaceutical company Merck, logistics firm FedEx subsidiary TNT Express, and Mondelez International among others, with total global damages estimated by the White House at approximately ten billion US dollars, representing one of the most economically destructive cyberattacks ever recorded. As a discrete campaign rather than an ongoing criminal group, NotPetya itself is not operationally active, though its parent threat actor Sandworm Team remains highly active and continues to conduct destructive cyber operations globally as of current reporting.

Most-targeted sectors

Most-affected countries

Recent disclosures by NotPetya

All 1 indexed disclosures. Click any row for the full per-victim dossier.

See every disclosure indexed for NotPetya

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Inactive ransomware operator

All groups

NotPetya

1 victims indexed · first seen 10 years ago · last activity 10 years ago

1
Victims indexed
#341 of 391 tracked operators
<1m
Active period
Jan 2017 → Jan 2017
1
Countries hit
top DK · 1

At a glance

Status
inactive
First seen
10 years ago
Last activity
10 years ago
Primary sector
Transportation · 1 hits

About

NotPetya is a destructive malware campaign — widely assessed by the intelligence community and leading cybersecurity researchers not as a traditional ransomware operation but as a cyberweapon disguised as ransomware — that emerged in June 2017 and caused catastrophic, indiscriminate damage to global organizations, with financial destruction rather than ransom collection assessed as a secondary concern to its primary destructive intent. Attributed with high confidence by the United States, United Kingdom, European Union, and Australia to Sandworm Team, a threat actor operating under Russia's GRU military intelligence directorate, NotPetya is not a Ransomware-as-a-Service operation but rather a state-sponsored destructive tool, with links to earlier Sandworm campaigns including the BlackEnergy and Industroyer attacks targeting Ukrainian critical infrastructure. NotPetya gained initial access primarily through the poisoned Ukrainian accounting software MeDoc, leveraging a trojanized software update mechanism as a supply chain attack vector, subsequently propagating laterally at extraordinary speed using the EternalBlue and EternalRomance NSA-derived exploits alongside the Mimikatz credential harvesting tool, with no genuine decryption capability ever offered — rendering it a wiper rather than functional ransomware. The campaign struck Danish shipping giant Maersk, pharmaceutical company Merck, logistics firm FedEx subsidiary TNT Express, and Mondelez International among others, with total global damages estimated by the White House at approximately ten billion US dollars, representing one of the most economically destructive cyberattacks ever recorded. As a discrete campaign rather than an ongoing criminal group, NotPetya itself is not operationally active, though its parent threat actor Sandworm Team remains highly active and continues to conduct destructive cyber operations globally as of current reporting.

Timeline

1 months
2017-01-01T00:00:00+00:00 · 1
2017-01-01T00:00:00+00:002017-01-01T00:00:00+00:00

Top countries

🇩🇰 Denmark
1

Top sectors

Transportation
1

MITRE ATT&CK

22 techniques · 8 tactics

Tactics

Initial AccessExecutionPrivilege EscalationCredential AccessLateral MovementDiscoveryDefense EvasionImpact

Techniques

  • T1190Exploit Public-Facing Application
  • T1566.001Phishing: Spearphishing Attachment
  • T1195.002Supply Chain Compromise: Compromise Software Supply Chain
  • T1059.003Command and Scripting Interpreter: Windows Command Shell
  • T1204.002User Execution: Malicious File
  • T1106Native API
  • T1068Exploitation for Privilege Escalation
  • T1055Process Injection
  • T1003.001OS Credential Dumping: LSASS Memory
  • T1550.002Use Alternate Authentication Material: Pass the Hash
  • T1210Exploitation of Remote Services
  • T1021.002Remote Services: SMB/Windows Admin Shares
  • T1072Software Deployment Tools
  • T1135Network Share Discovery
  • T1018Remote System Discovery
  • T1083File and Directory Discovery
  • T1036Masquerading
  • T1070.004Indicator Removal: File Deletion
  • T1486Data Encrypted for Impact
  • T1561.002Disk Wipe: Disk Structure Wipe
  • T1490Inhibit System Recovery
  • T1529System Shutdown/Reboot

Recent victims

Loading…

Source

Updated 10 years ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time NotPetya posts a victim.

Add NotPetya to your watchlist — Pro pings you within 5 minutes of any new NotPetya leak-site post, Telegram callout, or affiliate-rebrand inference.