What Was NotPetya? The Ransomware That Was Never Ransomware
The ransom note was a costume.
NotPetya encrypted the master file table, overwrote the master boot record, rebooted the machine, and displayed a demand for $300 in Bitcoin along with an installation key to send to the attackers.
There was no routine in the program capable of decrypting anything. The installation key was random data — not an encrypted key, not a derived identifier, just noise. Nobody was reading the mailbox. Paying accomplished exactly nothing, and it was never going to.
What was NotPetya?
NotPetya was a destructive wiper released on 27 June 2017, disguised as a variant of an existing ransomware family called Petya — hence the name the industry settled on, which is not a name anyone would choose on purpose.
In February 2018 the United States, the United Kingdom and several allied governments formally attributed it to the Russian military intelligence service, the GRU. The unit is commonly tracked as Sandworm.
The White House put total damages at approximately $10 billion, which makes it the most destructive cyberattack yet recorded, by a wide margin and with no serious competitor.
How it got in, and why that was so effective
Not by email. The initial vector was a backdoored update to M.E.Doc, a Ukrainian tax accounting package that any company filing taxes in Ukraine effectively had to run.
That is a precise choice. It is not a broad attack that happened to hit Ukraine; it is an attack whose delivery mechanism was, by construction, the set of organisations doing business in Ukraine. The multinationals that got destroyed — Maersk, Merck, FedEx's TNT division, Mondelez, Reckitt Benckiser — were hit because they had a Ukrainian office, and because that office was on the same network as everything else.
Once inside, it moved on its own. It used EternalBlue and EternalRomance, the same leaked NSA exploits behind WannaCry six weeks earlier, but it did not depend on them. It also harvested credentials from memory and used entirely legitimate administrative tools — PsExec and WMI — to move to machines that were fully patched.
That combination is why patching alone did not save anyone. A fully patched machine that trusted a compromised one still fell.
Maersk, and the domain controller in Ghana
Maersk moves close to a fifth of the world's shipping containers. NotPetya took the company down in under an hour.
The published account, given by chairman Jim Hagemann Snabe at Davos and reported in detail since, is roughly this: 4,000 servers, 45,000 workstations and 2,500 applications destroyed, and rebuilt in ten days. Terminals worldwide fell back to paper. Gates that could not read a booking number simply let trucks through.
Rebuilding an Active Directory forest requires at least one surviving domain controller, and every one of Maersk's had been wiped — with a single exception. A domain controller in Ghana had been offline during the attack because of a local power cut.
That machine held the only surviving copy of the directory. Because the link was too poor to transfer the data, a staff member flew it to the recovery site.
The entire recovery of one of the world's largest logistics companies rested on an electricity failure in West Africa.
Correcting the record
It was reported as ransomware for days, because it said it was ransomware, and because WannaCry had happened six weeks earlier and everyone had a template ready.
The tell was in the code. Researchers who compared it with the real Petya found that the original had a working recovery path and this did not. The victim identifier shown on screen was not derived from the encryption key, so even an attacker willing to help could not have reconstructed it. Some of what it overwrote was not recoverable under any circumstances.
The distinction matters commercially as well as technically. Ransomware has a business model, which means it has an incentive to be reversible — a family that never decrypts stops being paid. A wiper wearing a ransom note has no such constraint, and behaves accordingly.
It also matters legally. Merck claimed roughly $1.4 billion and its insurers refused, invoking the war exclusion on the grounds that this was a state attack. That argument ran through the courts for years before settling in 2024, and it changed how cyber insurance is written.
What is still true
The lesson people took was patching, and patching was the least of it. The durable ones are less comfortable.
A subsidiary's network is your network. Credential reuse across a flat estate turns one compromise into all of them. Administrative tooling that can reach every machine is an attack path that no patch closes. And an offline backup is only a backup if it is genuinely offline — Maersk survived on an accident, not a control.
Nobody has been charged in a court that can enforce it.
Further reading
- Andy Greenberg — Sandworm (2019), and his Wired feature on the Maersk recovery.
- ESET and Cisco Talos technical analyses of the M.E.Doc supply chain compromise, June-July 2017.
- The UK National Cyber Security Centre and US government attribution statements, February 2018.
- Merck & Co. v. ACE American Insurance, on the war exclusion.
EXHIBIT 0011 — NOTPETYA
We put it on a shirt. A padlock drawn as a technical cutaway, mounted across a hard disk, its mechanism solid — and no keyhole anywhere on it. Beside it, the ransom note, its key field filled with hexadecimal that means nothing.
Most people will read it as a lock. A smaller number will look for the keyhole.
That's the whole idea.