Case Study - Destructive Wiper Malware

Merck NotPetya Cyberattack

Year – 2017

Estimated Economic Losses – Industry estimates place global NotPetya damages at over US$10 Billion.

Systems Affected – Approximately 40,000 Merck systems were impacted globally across more than 60 countries were affected.

Type of Attack – Destructive Wiper Malware | Self-Propagating Network Worm

Suspected Group / Organization – Attributed by the United States, United Kingdom, and several allied governments to Sandworm (Unit 74455), an operational unit of Russia’s Main Intelligence Directorate (GRU).

Detailed Working
Attackers distributed NotPetya through a compromised M.E.Doc software update. Once executed, the malware stole credentials, spread rapidly across enterprise networks using EternalBlue, PsExec, and WMIC, and permanently destroyed system boot records and file structures. 

Forensic Investigations
Investigators analyzed malware samples, system and network logs, and disk artifacts to trace the attack. The investigation confirmed the compromised M.E.Doc update, credential theft, lateral movement, and destructive modifications to the Master Boot Record (MBR), leading to attribution of the attack to the Sandworm threat group.

+91-7087055115

sales@ryuzasecurity.com

Subscribe Now.

No content is added yet.