Intelligence Advisory – New Petya/Petna Ransomware Outbreak

June 28, 2017

The Petya and Petna outbreak represents a destructive Master Boot Record wiper campaign that weaponized the EternalBlue SMB exploit alongside administrative execution tools to compromise Windows environments, encrypt file systems, and permanently destroy storage partitions under the guise of financial extortion.

Threat Classification and Supply-Chain Origins

Malware classified as ransomware traditionally restricts access to user files or system resources until a specified ransom is remitted to the attacker. However, the June 2017 outbreak known alternately as Petna, NotPetya, ExPetr, and Nyetya departed from conventional cyber extortion schemes. While displaying ransom notes demanding cryptocurrency payments, the underlying code functioned as a destructive wiper designed to inflict permanent data loss and infrastructure degradation across government agencies, financial institutions, and global corporations.

The initial attack vector originated through a targeted supply-chain compromise of the Ukrainian financial accounting software MeDoc (developed by Intelligence Systems). Threat actors infiltrated the software vendor update servers, injecting malicious code into routine software updates. When client organizations downloaded the signed update package, the malicious payload was deployed directly into corporate networks across Ukraine and subsequently propagated worldwide.

Multi-Stage Infection Vectors and Lateral Movement

Once executing within a compromised host, Petna does not rely on a single infection mechanism. It combines automated vulnerability exploitation with credential theft to move horizontally across networks:

  • EternalBlue (MS17-010): The malware executes the EternalBlue exploit targeting a severe remote code execution vulnerability in the Microsoft Server Message Block version 1 (SMBv1) protocol, enabling unauthorized execution on unpatched hosts across local subnets.
  • EternalRomance: A complementary SMB exploit targeting Windows systems over port 445, providing alternative execution pathways across varying Windows operating system versions.
  • Memory Credential Harvesting: Petna contains an embedded credential extraction module based on Mimikatz. It dumps cleartext passwords and active NTLM hashes from the Local Security Authority Subsystem Service (LSASS) memory space.
  • PsExec and WMI Propagation: Utilizing the harvested administrator credentials, the malware executes commands on adjacent network servers and domain controllers via Windows Management Instrumentation (WMI) and the Microsoft PsExec administrative utility.

Master Boot Record (MBR) Overwriting and Destructive Encryption

Petna executes a dual-tier encryption sequence that systematically destroys file structures and partition tables. Upon gaining administrative privileges, the malware overwrites sector zero of the physical disk - the Master Boot Record (MBR) - with a custom bootloader routine. It then initiates a scheduled system crash or forced restart using the Windows shutdown command.

Upon rebooting, the malicious bootloader takes control before the operating system initializes. It displays a simulated Chkdsk text screen informing the user that the file system is being repaired. In reality, the malware encrypts the Master File Table (MFT) of NTFS partitions using the Salsa20 encryption algorithm. Unlike standard Petya variants where an encryption key is derived and recoverable, Petna generates a completely random installation key that is never transmitted to command-and-control servers. Consequently, the encryption key cannot be computed, rendering data recovery technically impossible.

Victims were directed to transfer US$ 300 in Bitcoin to a designated wallet address and communicate through a German webmail account (wowsmith123456@posteo.net). The email provider shut down the associated inbox within hours of the outbreak. Because the communication channel was severed and the mathematical key generation was irreversible, paying the ransom produced zero decryption outcomes.

Global Supply Chain Impact and Critical Infrastructure Disruption

The campaign inflicted severe financial and operational damage on multinational enterprises operating worldwide:

  • A.P. Moller-Maersk: The global shipping and container terminal conglomerate suffered complete IT outages across multiple port terminals and headquarters, forcing manual container processing and causing estimated losses exceeding $300 million.
  • Merck and Co.: The global pharmaceutical company experienced extensive disruptions to active pharmaceutical ingredient manufacturing and distribution systems.
  • FedEx (TNT Express): The international logistics carrier suffered persistent record losses and delivery halts across its European distribution hubs.
  • Critical Infrastructure: Ukrainian government ministries, the central bank, electrical utilities, metro ticketing systems, and radiation monitoring networks at Chernobyl faced severe automated shutdowns.

Digital Forensics and Memory Analysis Observations

Digital forensics investigators analyzing infected physical drives observed that Petna deliberately writes junk bytes over the primary MBR and partition boot records before initiating encryption. Memory dumps collected from active endpoints revealed that the malware actively terminates security telemetry agents and attempts to clear Windows Event Logs (Application, Security, and System logs) using wevtutil.exe to hinder post-incident reconstruction. Incident response teams must preserve raw disk bitstream images and uncorrupted RAM snapshots immediately to conduct thorough artifact extraction and establish lateral traversal timelines.

Enterprise Mitigation Strategies and Incident Response Architecture

Mitigating advanced wiper threats requires rigorous endpoint hardening, network isolation, and resilient disaster recovery mechanisms:

  • Immediate MS17-010 Patch Deployment: Apply all cumulative security updates released under Microsoft Security Bulletin MS17-010 across desktop and server operating systems.
  • Strict Disablement of SMBv1: Deactivate the obsolete SMB version 1 protocol across all Windows endpoints via Group Policy or PowerShell execution, enforcing SMBv2 or SMBv3 encryption.
  • Network Segmentation and Port Filtering: Block inbound and outbound TCP ports 139 and 445 at boundary firewalls and restrict inter-workstation communication within local area network subnets.
  • Privilege Management and LAPS Implementation: Enforce the Principle of Least Privilege, implement the Local Administrator Password Solution (LAPS) to prevent password reuse, and restrict Domain Administrator accounts from logging into standard endpoints.
  • Immutable and Air-Gapped Backups: Maintain regular offline, air-gapped, and write-once-read-many (WORM) backups of critical databases, virtual machine disks, and Active Directory system states.
  • Endpoint Detection and Behavioral Monitoring: Configure endpoint security agents to block unauthorized writes to raw disk sectors (PhysicalDrive0) and alert on unusual PsExec or WMI execution chains.

Security practitioners should regularly review technical advisories published by government agencies like CERT-In to verify emerging threat indicators. Aligning institutional incident response with cybersecurity compliance and digital risk governance safeguards business continuity, while evaluating critical infrastructure administrative directives provides operational depth for mandatory incident reporting and corporate accountability standards.

Found this helpful?

Share this page with others