Back to the archive

NotPetya attack

Kyiv, Ukraine (global spread), June 2017

Case summary

On 27 June 2017, NotPetya, a wiper disguised as ransomware, was distributed through the update server of Ukrainian accounting software M.E.Doc and paralysed global companies within hours. Estimated damage exceeded $10 billion; the US, UK and allies attributed the attack to Russian military intelligence (GRU) in 2018.

Timeline

  1. 2017-06-27Initial infection via an M.E.Doc update; banks, the airport and ministries hit in Ukraine.
  2. 2017-06-27Spread to global firms including Maersk, Merck, FedEx/TNT and Rosneft.
  3. 2017-06-28Analysis showed the encryption was irreversible; the goal was destruction, not ransom.
  4. 2017-07-04Ukrainian police seized M.E.Doc's servers.
  5. 2018-02-15The White House and the UK attributed the attack to the Russian military.
  6. 2020-10-19The US DOJ indicted six officers of GRU Unit 74455 (Sandworm).

People and connections

  • Sandworm (GRU 74455)

    The attributed operator unit; subject of the 2020 indictment.

  • M.E.Doc

    The software firm whose update channel was the supply-chain entry point.

  • EternalBlue / Mimikatz

    The exploit and credential tool combined for lateral spread.

  • Maersk

    Among the most visible victims; rebuilt 4,000 servers and 45,000 endpoints.

  • Sandworm (GRU 74455) to M.E.DocCompromise of the update server (supply chain)
  • M.E.Doc to MaerskSpread from a single Ukraine-office install to the global network

Findings

  • That the initial vector was M.E.Doc's update mechanism is verified by independent analyses.

    Assessment: VerifiedSource: ESET, Cisco Talos and Ukrainian police2017-07
  • The malware was engineered so payment could not recover data; it is classed as a wiper.

    Assessment: VerifiedSource: Kaspersky and Matt Suiche analyses2017-06
  • GRU attribution is supported with high confidence by a five-country joint statement and the 2020 indictment, though no court verdict exists.

    Assessment: ProbableSource: DOJ indictment2020-10
  • Total-damage estimates ($10–12bn) rest on insurance and corporate reporting; no definitive figure exists.

    Assessment: ContestedSource: White House estimate2018-02

Documents

Sources

  1. The Untold Story of NotPetya

    WIRED (Andy Greenberg), 2018, In-depth investigation

    Open
  2. Six Russian GRU Officers Charged

    US Department of Justice, 2020, Official indictment

    Open
  3. NotPetya technical analysis

    ESET WeLiveSecurity, 2017, Technical analysis

    Open
  4. Statement on NotPetya attribution

    White House / NCSC, 2018, Official attribution statement

    Open

Locations

  • Kyiv (M.E.Doc HQ)50.45°, 30.52°
  • Copenhagen (Maersk HQ)55.68°, 12.57°

Researcher's note

What caught my attention here was how quickly the early ransomware label became misleading. Code overlap alone was not enough for attribution; infrastructure, targets, timing, and the later formal investigation had to be read together.

Recent checks

  1. 2026-05-30Source URLs checked; the NCSC attribution page had moved, archive link added.