Malware.View on attack.mitre.org
NotPetya is malware that was used by Sandworm Team in a worldwide attack starting on June 27, 2017. While NotPetya appears as a form of ransomware, its main purpose was to destroy data and disk structures on compromised systems; the attackers never intended to make the encrypted data recoverable. As such, NotPetya may be more appropriately thought of as a form of wiper malware. NotPetya contains worm-like features to spread itself across a computer network using the SMBv1 exploits EternalBlue and EternalRomance.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
NotPetya contains a modified version of Mimikatz to help gather credentials that are later used for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
NotPetya can use PsExec, which interacts with the |
| T1036 Masquerading |
|
| T1047 Windows Management Instrumentation |
NotPetya can use |
| T1053.005 Scheduled Task |
NotPetya creates a task to reboot the system one hour after infection. |
| T1078.003 Local Accounts |
NotPetya can use valid credentials with PsExec or |
| T1083 File and Directory Discovery |
NotPetya searches for files ending with dozens of different file extensions prior to encryption. |
| T1210 Exploitation of Remote Services |
NotPetya can use two exploits in SMBv1, EternalBlue and EternalRomance, to spread itself to other remote systems on the network. |
| T1218.011 Rundll32 |
NotPetya uses |
| T1486 Data Encrypted for Impact |
NotPetya encrypts user files and disk structures like the MBR with 2048-bit RSA. |
| T1518.001 Security Software Discovery |
NotPetya determines if specific antivirus programs are running on an infected host machine. |
| T1529 System Shutdown/Reboot |
NotPetya will reboot the system one hour after infection. |
| T1569.002 Service Execution |
NotPetya can use PsExec to help propagate itself across a network. |
| T1685.005 Clear Windows Event Logs |
NotPetya uses |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.