Thursday, April 24, 2025
HomeRansomwareAnother Biggest Ransomware "Petya" Attacked and Perform Massive Breach in Large Number...

Another Biggest Ransomware “Petya” Attacked and Perform Massive Breach in Large Number of Countries Across the Globe – What to do if you are affected

Published on

SIEM as a Service

Follow Us on Google News

Again Ransomware Back to Form !!! A Ransomware called “Petya” Attack Large  Number of Countries across the Globe and it affecting a large number of banks, energy firms and other companies based in Russia, Ukraine, Spain, Britain, France,India,etc..

Few weeks Before Wannacry  Ransomware performed Massive breaches across the world and now petya Ransomware threatens the around the world and spread rapidly.

Also Read    New Ransomware, Attack Android Phones which Looks like Wannacry

- Advertisement - Google News

This Ransomware attack Started in Ukraine First, Especially Ukraine’s government, banks, state power utility and Kiev’s airport and the metro system have infected by Petya very badly then its Spreading Across the World.

Petya Ransomware Displayed in  infected Machine that, “your files are no longer Accessible  and since your All the Files are encrypted asks  300$ Ransom amount from the Each Infected Computers”

According to  Independent, UK’s National Cyber Security Centre says, We’re aware of the global ransomware incident and are monitoring the situation closely.

Russian Super Market computer systems have fully infected by this Petya Ransomware.

Danish shipping company Maersk IT Systems Twitted that Multiple Sites and Business units are down by this Massive Petya Ransomware Cyber Attack.

Also Read    A Fileless Ransomware Called “SOREBRECT” Discovered with Code Injection Capability that Encrypts local and Network Share Files

How Does Petya Ransomware Attack

Petya Ransomware once entered into the Machine, First, in the attack the NTFS partitions contain MFT (Master File Tree) table and overwrites the MBR (Master Boot Record) with its Malicious code.

After “Master Boot Record” Over Ride by the Malicious code then it restricting access to the full system and its leads to unable to boot the systems and its finally shows the Ransom Notes that contain the information about the Payment and etc.

Petya Ransomware using email Spam in the form of Office documents to spread into the Network.

Petya Author provides contact details of wowsmith123456@posteo.net and asks for a payment of $300 in Bitcoin.

According to Symantec, Petya Using similar function of SMB work based on the NSA’s ETERNALBLUE exploit which is used by Wannacry Ransomware and this has been confirmed by another security firms Payload Security, Avira, Emsisoft, Bitdefender, Researchers.

Petya ransomware works it combines both a client-side attack (CVE-2017-0199) and a network-based threat (MS17-010)

A complete Indicator of Attacks (IOC) for Petya Ransomware Document  uploaded  in GitHub

According to virustotal Malware Scanning Engine Detected that 21 out of 61 AV vendors successfully indicated and updated Petya varients.

List of companies Infected by Petya

  1. Ukraine’s central bank, the National Bank of Ukraine.
  2. Ukrainian bank Oschadbank.
  3. Ukrainian delivery service company Nova Poshta.
  4. Russian state oil giant Rosneft.
  5. Kyivenergo, Kiev power company.
  6. Radiation monitoring system at Chernobyl.
  7. Website of Kiev’s Boryspil International Airport.
  8. Danish sea transport company Maersk.
  9. British advertising giant WPP.
  10. French industrial group Saint-Gobain.
  11. US pharmaceutical giant Merck.
  12. Spanish food giant Mondelez.
  13. Spanish global legal firm DLA Piper

What to do if you are affected?

The ransomware infects PCs and afterward sits tight for around an hour prior rebooting the machine. While the machine is rebooting, you can turn the PC off to keep the files from being encrypted and try and rescue the files from the machine, by @hackerfantastic.

If the system reboots with the ransom note, don’t pay for it, there is no way back to get the decryption key back as the Email address is shut down. You can for restoring the backup.

Security researcher Amit Serper found a kill switch “Temporary fix” for Petya Outbreak. The suggested method is to block the process that tries to open Harddisk0\\DR0 or “C:\Windows\perfc” with the write request.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Verizon DBIR Report: Small Businesses Identified as Key Targets in Ransomware Attacks

Verizon Business's 2025 Data Breach Investigations Report (DBIR), released on April 24, 2025, paints...

Lazarus APT Targets Organizations by Exploiting One-Day Vulnerabilities

A recent cyber espionage campaign by the notorious Lazarus Advanced Persistent Threat (APT) group,...

ToyMaker Hackers Compromise Numerous Hosts via SSH and File Transfer Tools

In a alarming cybersecurity breach uncovered by Cisco Talos in 2023, a critical infrastructure...

Threat Actors Exploiting Unsecured Kubernetes Clusters for Crypto Mining

In a startling revelation from Microsoft Threat Intelligence, threat actors are increasingly targeting unsecured...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Verizon DBIR Report: Small Businesses Identified as Key Targets in Ransomware Attacks

Verizon Business's 2025 Data Breach Investigations Report (DBIR), released on April 24, 2025, paints...

ToyMaker Hackers Compromise Numerous Hosts via SSH and File Transfer Tools

In a alarming cybersecurity breach uncovered by Cisco Talos in 2023, a critical infrastructure...

Ransomware Actors Ramp Up Attacks Organizations with Emerging Extortion Trends

Unit 42’s 2025 Global Incident Response Report, ransomware actors are intensifying their cyberattacks, with...