Netskope Threat Labs

Petya

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Petya is disk encrypting ransomware that overwrites the boot sector and core file system structures to prevent system startup, destroying data rather than merely locking files. First observed in 2016 through phishing campaigns, the family evolved into the NotPetya outbreak of June 2017, which masqueraded as ransomware while acting as a wiper and caused billions of dollars in damage worldwide. The lineage remains the clearest example of ransomware adapted for mass disruption.

First seen
March 2022
Last seen
October 2026
Alert Name
Gen:Variant.Ransom.Petya.9
Script-JS.Downloader.Petya
Trojan.Ransom.Petya.A
Trojan.Ransom.Petya.C
Trojan.Ransom.Petya.G
Trojan.Ransom.Petya.Gen.1
Trojan.Ransom.Petya.H
Trojan.Ransom.Petya.M
Trojan.Ransom.Petya.N
VB:Trojan.VBA.Petya.C