NotPetya

2017-06-27

The 27 June 2017 destructive cyber operation that began as a Ukrainian-targeted attack via a supply-chain compromise of the M.E.Doc accounting software and spread globally within hours, weaponising the leaked NSA EternalBlue SMB exploit for lateral movement. The operation is the most economically destructive cyber attack in history — approximately $10 billion in damages worldwide — and was attributed to GRU Unit 74455 (Sandworm) by the Five Eyes intelligence partners in February 2018. Indicted as part of the United States Department of Justice's 19 October 2020 charging of six GRU officers.

0:00 / 0:00

Audio readout of this entry.

Background

NotPetya was the operational descendant of two prior Russian-attributed cyber operations against Ukraine: the BlackEnergy attack of 23 December 2015, in which GRU Unit 74455 conducted the first publicly-documented cyber-induced electricity outage by compromising three Ukrainian regional electricity-distribution operators and remotely toggling their substations offline; and the Industroyer attack of 17 December 2016, in which the same unit deployed the first operational malware specifically designed to manipulate industrial-control-system protocols against Ukrenergo's substations in Kyiv. The 2015–2016 attacks established Unit 74455's institutional capability for destructive cyber operations and its operational targeting against Ukrainian critical infrastructure, but neither operation spread beyond the immediate Ukrainian targets.1

The April 2017 Shadow Brokers leak — the unidentified actor's public release of a substantial portion of the NSA Tailored Access Operations exploit cache — included the EternalBlue SMBv1 exploit and the DoublePulsar implant. EternalBlue exploited a vulnerability in the Microsoft Server Message Block (SMB) v1 protocol that permitted remote-code-execution against unpatched Windows systems on the same network segment as the attacker. Microsoft had patched the underlying vulnerability on 14 March 2017 (security update MS17-010), but a substantial population of unpatched systems remained operational in the months following the patch release. The May 2017 WannaCry ransomware outbreak — an unattributed operation widely though not conclusively associated with the Lazarus Group — was the first weaponisation of EternalBlue in a destructive cyber operation; NotPetya, six weeks later, was the second.2

The third operational antecedent was the M.E.Doc accounting-software ecosystem in Ukraine. M.E.Doc — produced by the Kyiv-based Intellect Service LLC — was the dominant Ukrainian tax-accounting software, used by approximately 80 percent of Ukrainian businesses for compliance reporting to Ukrainian tax authorities. The M.E.Doc product automatically distributed updates from the Intellect Service infrastructure to all installed clients. The intrusion of the M.E.Doc software-update infrastructure — assessed by subsequent investigation to have begun in approximately April 2017 — gave the operators a supply-chain delivery channel through which to push a weaponised payload to substantially the entire Ukrainian business population in a single update push.3

The Operation

On 27 June 2017, at approximately 10:30 UTC, the Intellect Service M.E.Doc update server pushed a tainted software update to its installed-base of approximately several hundred thousand Ukrainian client systems. The tainted update carried the NotPetya payload — a 380-kilobyte Windows-executable file. On execution, the payload conducted three categories of action in sequence: lateral movement across the local network using the EternalBlue exploit (against unpatched systems) and the Mimikatz-derived credential-extraction tooling (against patched systems with weak network-segmentation); encryption of the master file table and boot sector of every reachable Windows system; and presentation of a ransom-demand interface requesting approximately $300 in Bitcoin for decryption.4

The ransom-demand interface was the operational deception. NotPetya was not ransomware. The master-file-table-encryption operation it conducted was not reversible by any operator-side decryption key — the encryption-key generation was deliberately constructed to produce keys that could not be recovered after the encryption operation completed. The ransom demand existed solely to delay the affected organisations' realisation that the data was unrecoverable and to obscure the operation's destructive character. The technical analysis of the operation, published by Kaspersky Lab on 28 June 2017 (the day following the attack) and corroborated by ESET Research and Comae Technologies in subsequent days, established the wiper character within approximately 24 hours of the initial outbreak.5

The lateral-movement chain was the operationally consequential element. Within Ukrainian organisations, NotPetya spread from the initially-infected M.E.Doc-running systems to substantially the entire enterprise network within minutes. From Ukrainian organisations with international networks — and specifically from the Ukrainian subsidiaries of multinational corporations — the malware propagated through corporate-VPN and inter-office-WAN infrastructure into the parent organisations' global networks. The first major non-Ukrainian victims were detected in Western Europe within approximately three hours of the initial Ukrainian outbreak; the global spread was substantially complete within twelve hours.6

Documented victims and damages

The most extensively-documented victim organisations and their reported damages:

A.P. Møller–Maersk — the Danish shipping conglomerate, the world's largest container-shipping operator. Maersk's Ukrainian subsidiary network was the initial infection vector for the parent organisation. Within hours, NotPetya had spread to the substantial majority of Maersk's global IT infrastructure. The company's account, subsequently disclosed in detail by chairman Jim Hagemann Snabe at the January 2018 World Economic Forum and in Andy Greenberg's 2019 book Sandworm, was that approximately 45,000 PCs, 4,000 servers, and 2,500 applications were destroyed; the company was offline for approximately ten days; and the total damage was reported as approximately $250 million to $300 million. The recovery was structurally improbable — Maersk's domain-controller infrastructure was substantially destroyed, and the recovery proceeded on the basis of a single surviving domain controller in the company's Ghana office that had been offline due to a power outage during the attack.7

Merck & Co. — the United States pharmaceutical company. Merck reported NotPetya damages of approximately $870 million in initial 10-K filings, subsequently revised upward to approximately $1.4 billion across multiple fiscal periods. Merck's NotPetya-attributable losses include direct IT remediation costs, manufacturing disruption (particularly in the company's HPV vaccine production line), lost sales, and substantial subsequent insurance-coverage litigation against ACE American Insurance Company and other insurers over the application of the "hostile or warlike action" exclusion to NotPetya as an "act of war." The Merck v. ACE insurance litigation — Merck & Co., Inc. v. ACE American Insurance Co., settled on appeal in the New Jersey Appellate Division in May 2023 with a finding in Merck's favour — is the canonical American case-law authority on cyber-insurance coverage of state-attributed cyber operations and the war-exclusion question.8

FedEx (TNT Express subsidiary). TNT Express, the Dutch logistics firm FedEx had acquired in 2016, was substantially destroyed by NotPetya. TNT's IT infrastructure was reported as approximately 95 percent destroyed; the company's operations were degraded for several weeks; and FedEx's total NotPetya damages were reported as approximately $400 million.9

Mondelez International — the United States multinational confectionery and food company. Mondelez reported NotPetya damages of approximately $100 million and subsequently filed suit against its insurer, Zurich American, over the application of the war-exclusion clause. The Mondelez Int'l, Inc. v. Zurich Am. Ins. Co. case settled in 2022.10

Saint-Gobain. The French multinational manufacturer of construction materials reported NotPetya damages of approximately €250 million.11

Reckitt Benckiser, Beiersdorf, Nuance Communications, Cadbury (Mondelez subsidiary), DLA Piper. Each reported damages in the tens to low hundreds of millions of US dollars; the cumulative total across all documented enterprise victims is the basis for the approximately $10 billion total-economic-damage estimate that is the canonical figure cited in subsequent literature, traceable to United States Council of Economic Advisers analysis released in 2018 and the White House February 2018 attribution statement.12

Ukrainian central institutions. The Ukrainian central bank, the Kyiv Boryspil International Airport, the Chornobyl radiation-monitoring system, the Ukrainian state postal service Ukrposhta, the Ukrainian state power-distribution operator Ukrenergo (also a victim of the prior Industroyer attack), and substantially the entire Ukrainian government information-systems infrastructure were degraded or destroyed in the initial Ukrainian outbreak. The Chornobyl manual radiation-monitoring operation was the subject of contemporaneous Ukrainian government statements emphasising that the Chornobyl reactor-shelter automated systems had remained operational while the surrounding administrative systems were destroyed.13

Attribution

The Five Eyes joint attribution of NotPetya to the Russian Federation, and specifically to the Russian military, was announced on 15 February 2018 in coordinated statements from the United States White House, the United Kingdom National Cyber Security Centre, the Australian government, the Canadian government, and the New Zealand government. The White House statement read: "In June 2017, the Russian military launched the most destructive and costly cyber-attack in history. The attack, dubbed 'NotPetya,' quickly spread worldwide, causing billions of dollars in damage across Europe, Asia, and the Americas. It was part of the Kremlin's ongoing effort to destabilize Ukraine and demonstrates ever more clearly Russia's involvement in the ongoing conflict. This was also a reckless and indiscriminate cyber-attack that will be met with international consequences."14

The United Kingdom NCSC statement specifically attributed the operation to the Russian military and assessed "with high confidence" that the Russian government, specifically the Russian military, was responsible. The NCSC statement noted that the attack masqueraded as a criminal enterprise but its purpose was disruption rather than financial gain. The Five Eyes attribution was the broadest public attribution of a state-cyber operation to that point in the public record.15

The institutional attribution to GRU Unit 74455 — the GRU's Main Centre for Special Technologies, the destructive-cyber-operations unit — was specified in the United States Department of Justice indictment of 19 October 2020, which named six Unit 74455 officers as defendants on charges including conspiracy to commit computer fraud, wire fraud, and aggravated identity theft. The indictment specifies NotPetya as one of the operations on which the named defendants are charged.16

The European Council, in Council Decision (CFSP) 2020/1537 of 22 October 2020, imposed targeted sanctions against the GRU Centre 18 leadership and against four officers of GRU Unit 74455 specifically in connection with NotPetya and the related operations of the 2017–2020 period.17

Significance

NotPetya is the most economically destructive cyber operation in history, by approximately one order of magnitude over the next-largest publicly-attested case. The approximately $10-billion total-damage figure is itself probably a lower bound — substantial damages went unreported in corporate disclosures for liability and reputational reasons. The operation established several institutional precedents that have substantially shaped the subsequent cyber-policy environment:

  • The operation made clear that supply-chain compromise of routinely-trusted software-update channels could deliver state-cyber payloads to a substantial population of enterprise networks in a single push, without target organisations having any opportunity to refuse the delivery. This realisation substantially structured the subsequent attention to software-supply-chain security across the Western government and enterprise-IT sectors.
  • The operation made clear that the geographic-targeting boundaries assumed by attackers can fail catastrophically: an operation designed against Ukrainian targets propagated globally within hours through the international subsidiary networks of Ukrainian-operating multinationals. The institutional response — better enterprise-network segmentation against lateral movement, particularly between national operating subsidiaries — has been a sustained post-2017 priority for multinational IT operations.
  • The operation made clear that destructive-cyber operations targeting national-civilian infrastructure of one state could impose substantial economic damage on the multinational corporations and the national-civilian infrastructures of other states, with no operational targeting against those secondary victims. The subsequent insurance-litigation cycle (Merck v. ACE, Mondelez v. Zurich) is the institutional working-through of the resulting cyber-insurance and war-exclusion questions.
  • The operation made clear that the EternalBlue exploit, once stolen from NSA TAO and publicly leaked by Shadow Brokers, would be weaponised by other state and non-state cyber actors with damages in the billions of dollars. The subsequent Vulnerabilities Equities Process reforms in the United States executive branch — particularly the 2017 White House revisions to the VEP charter — are the institutional response to the demonstrated downside of stockpiled offensive-cyber capability.18

Sources & Further Reading

  1. Andy Greenberg, Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin's Most Dangerous Hackers (Doubleday, 2019), Chapters 8–10 — the canonical secondary source on the BlackEnergy and Industroyer operations as institutional antecedents to NotPetya. SANS Industrial Control Systems, Analysis of the Cyber Attack on the Ukrainian Power Grid (18 March 2016).
  2. Microsoft Security Bulletin MS17-010 (14 March 2017); Shadow Brokers public release on Steemit (14 April 2017); Microsoft Security Response Center, Customer Guidance for WannaCrypt attacks (12 May 2017).
  3. ESET Research, Analysis of TeleBots' cunning backdoor (4 July 2017); Cisco Talos Intelligence Group, The MeDoc Connection (5 July 2017) — the canonical technical reconstructions of the M.E.Doc supply-chain compromise.
  4. Kaspersky Lab Global Research and Analysis Team, ExPetr / Petya / NotPetya is a Wiper, Not Ransomware (28 June 2017); Matt Suiche (Comae Technologies), Petya 2017 is a wiper not a ransomware (28 June 2017).
  5. Kaspersky Lab, op. cit.; Suiche, op. cit.; ESET Research, op. cit.
  6. Andy Greenberg, Sandworm, op. cit., Chapter 14–17 — the canonical secondary source on the global propagation and the Maersk recovery; Andy Greenberg, The Untold Story of NotPetya, the Most Devastating Cyberattack in History, Wired (22 August 2018).
  7. Jim Hagemann Snabe (Maersk Chairman), remarks at the World Economic Forum panel (25 January 2018); Greenberg, Sandworm, op. cit., Chapter 14 on the Maersk recovery and the Ghana domain-controller story; Greenberg, Wired, op. cit.
  8. Merck & Co., Inc. 10-K Annual Reports for fiscal years 2017–2019, NotPetya-attributable disclosures; Merck & Co., Inc. v. ACE American Insurance Co., Docket No. UNN-L-2682-18, Superior Court of New Jersey, Union County, Law Division — Civil Part; Appellate Division decision, May 2023. Coverage analysis in Law360, Insurance Journal, and the Risk Management Magazine across 2023.
  9. FedEx Corporation, 10-K Annual Report for fiscal year 2017 — NotPetya-attributable disclosures; subsequent reporting in Reuters on the TNT damage.
  10. Mondelez International, Inc. 10-K disclosures; Mondelez Int'l, Inc. v. Zurich Am. Ins. Co., Cook County, Illinois Circuit Court; settlement reported in Wall Street Journal coverage of November 2022.
  11. Compagnie de Saint-Gobain, financial communications for H2 2017; Greenberg, Sandworm, op. cit.
  12. United States Council of Economic Advisers, The Cost of Malicious Cyber Activity to the U.S. Economy (February 2018) — the canonical United States Government estimate of approximately $10 billion in NotPetya damages, used in subsequent secondary-literature citation; subsequent reporting in Wired, Reuters, and the Financial Times across 2017–2020.
  13. Ukrainian government statements (Interior Ministry, State Service for Special Communications and Information Protection) of 27–30 June 2017; subsequent academic analysis in Survival and Intelligence and National Security.
  14. White House, Statement from the Press Secretary (15 February 2018) — the United States attribution of NotPetya to the Russian military.
  15. United Kingdom National Cyber Security Centre, Russian military 'almost certainly' responsible for destructive 2017 cyber attack (15 February 2018); parallel attribution statements from Australia, Canada, and New Zealand on the same date.
  16. United States v. Yuriy Sergeyevich Andrienko et al., Indictment, U.S. District Court for the Western District of Pennsylvania (15 October 2020), available at justice.gov. The indictment names six Unit 74455 officers — Yuriy Andrienko, Sergey Detistov, Pavel Frolov, Anatoliy Kovalev, Artem Ochichenko, and Petr Pliskin — and charges them in connection with NotPetya and four other operations.
  17. Council Decision (CFSP) 2020/1537 (22 October 2020), available through the EUR-Lex EU legal-documents portal.
  18. Vulnerabilities Equities Process charter revisions, November 2017; Eric Geller, Trump administration unveils its cyber rules of engagement, Politico (15 November 2017); subsequent academic analysis in Yale Journal of Law and Technology and Berkeley Journal of International Law.