First reportedJune 27, 2017
ActivityJune 27, 2017
Last updatedFeb 2, 2026, 12:00 AM UTC
Record confidencemed

Key facts

Affected

  • Organizations in Ukraine
  • Global organizations impacted by NotPetya propagation

Initial access

  • unknown

Impact

  • service_disruption
  • financial_loss
  • unknown

Attribution

Russia (Russian military) high confidence

U.S. and UK government public statements attributed NotPetya to Russia’s military.

CVEs and ATT&CK

CVEs

ATT&CK techniques

  • T1485: Security advisories describe NotPetya as destructive and not reliably recoverable, consistent with data destruction impact.

Mitigations

Now

  • Ensure tested offline/immutable backups and incident recovery proceduresDestructive outbreaks require rapid restore capability when data cannot be recovered.

Soon

  • Apply Windows security updates and reduce lateral movement paths (segmentation, SMB restrictions)Limits propagation mechanisms and reduces enterprise-wide impact.

Later

  • Strengthen supply-chain and software update verification for critical regional dependenciesOutbreaks can begin via regional software ecosystems; controlling trusted update channels reduces risk.

Detection ideas

Detect destructive behaviors and rapid system-wide changes

Alert on rapid file overwrites, disk/boot configuration modification attempts, and execution of malware-like binaries across many hosts.

Data sources: EDR telemetry, File integrity monitoring, Windows Security Event Logs

Detect lateral movement surges during outbreak conditions

Look for sudden spikes in SMB/RPC activity, remote service creation, and repeated authentication attempts across subnets.

Data sources: NetFlow/flow logs, Firewall logs, Windows Security Event Logs

Sources