Description
NotPetya is a 20217 wiper disguised as ransomware that initially targeted Ukrainian infrastructure, but quickly spread globally. It is attributed to Sandworm, a Russian millitary intelligence unit, and was responsible fro the cosliest cyberattack ever.
Stats
- First seen
- January 2023
- Last seen
- October 2026
Also known as
ExPetrGoldenEyeGoldeneyePetrWrap
MITRE ATT&CK techniques
14 techniques across 7 tactics.
TA0002 Execution
TA0005 Stealth
TA0007 Discovery
TA0008 Lateral Movement
Associated groups
Alert name variants
| Alert Name |
|---|
| Boot.Ransomware.GoldenEye |
| Document-Excel.Ransomware.GoldenEye |
| Document-Excel.Trojan.Goldeneye |
| Dropped:Trojan.Ransom.GoldenEye.B |
| Dump:Generic.Ransom.GoldenEye.6A1DA6F2 |
| Gen:Variant.Ransom.ExPetr.2 |
| Generic.Ransom.GoldenEye.2487E67A |
| Generic.Ransom.GoldenEye.494A7C33 |
| Generic.Ransom.GoldenEye.558FCDEC |
| Generic.Ransom.GoldenEye.7D78CD7F |


