Skip to main content

2017 · Multiple (shipping, pharmaceutical, manufacturing)

NotPetya

Destructive malware distributed through a compromised software update mechanism spread rapidly across enterprise networks worldwide, halting operations at manufacturers, logistics operators and pharmaceutical companies.

Indirect operational impactGlobal, originating in Ukraine

What happened

A supply-chain compromise of a widely used Ukrainian accounting software update delivered wiper malware that used credential theft and SMB exploitation to spread, rendering systems unusable.

Who

Attributed by several governments to a Russia-associated military intelligence group.

Where

Global, with heaviest early impact in Ukraine.

Why

Assessed objective: destructive disruption; collateral global impact followed.

How

Compromised update channel, then automated propagation using stolen credentials and a known SMB vulnerability.

Timeline

  1. 27 June 2017Malicious update distributed; global propagation within hours
  2. July 2017 onwardsMulti-week recovery efforts at affected multinationals

Attack path

Described at the level required to build detection and controls.

Initial Access

Reported

Compromised software update channel

IT foothold

Reported

Credential theft and automated propagation

Impact

Reported

Destruction of enterprise systems

Operational consequence

Reported

Production and logistics halted

Impact

OT impactPublic reporting focuses on enterprise system destruction; production stopped largely due to lost business systems and precautionary isolation.
Safety impactNo publicly documented safety impact.
Operational impactTerminal operations, manufacturing lines and distribution halted for days to weeks at multiple organisations.
Detected byImmediate, unavoidable — systems became unusable within minutes.

Technology involved

Windows enterprise estatesDomain infrastructureBusiness systems supporting operations

ATT&CK techniques

T0866T0867

Vulnerabilities and weaknesses exploited

  • A previously patched SMB vulnerability was used for propagation alongside credential theft

Control failures

  • Flat enterprise networks
  • Shared administrative credentials
  • IT/OT dependencies without isolation options
  • Recovery capability overwhelmed

Where earlier detection was possible

  • Not primarily a detection problem: segmentation, credential hygiene and recoverable backups were the decisive factors

Defensive lessons

  • Operations can stop even when controllers are untouched
  • You need a practised way to isolate OT from IT quickly
  • Tested, offline recovery capability defines how long the outage lasts

Why should I care?

Case studies are only useful if they change something. Pick one lesson above and check whether the control exists in your own environment this week.