NotPetya attack – three years on, what have we learned? null


Why was this particular trojan so successful – what was so special about it?
The attack was well prepared by its authors. NotPetya initially spread via the M.E.Doc accounting software when cybercriminals hacked the software’s update mechanism to spread NotPetya to systems when the software was updated. This was a bitter paradox, as users are always advised to update their software, but in this particular case, a trojanized updater of this software started the infection chain.This type of supply chain attack was not common at that time, causing a delay in figuring out the root cause of the attack. The speed at which it spread through the infected networks was fascinating.
The trojan was allegedly taking advantage of a long known vulnerability: (what) have companies/organizations learned from this?
For its lateral movement, NotPetya employed three different spreading methods: exploiting EternalBlue (known from WannaCry), exploiting EternalRomance, and via Windows network shares by using victim’s stolen credentials (this was done via a bundled Mimikatz-like tool, which extracts passwords) and legitimate tools like PsExec and WMIC. These additional techniques, which included exploiting known vulnerabilities for which patches were long available for, were probably the reason why it succeeded, despite EternalBlue gaining attention after the WannaCry attack less than two months before the NotPetya attack. I can only hope that companies learned to update their operating systems and applications as soon as an update becomes available, despite NotPetya, unfortunately, spreading via a product update.
Could the spread happen again in this form at any time?
It’s only a matter of time before there will be another major malware outbreak, when and how widespread the attack will be depends on multiple factors, including the availability of a high-quality exploit like EternalBlue, the malware actor, and their motivation.
Microsoft did a good job of patching EternalBlue, and the vulnerability is now mainly only present in older systems like Windows 7 and Windows XP. Of the PCs Avast scanned from May 23 – June 22, 2020, only 4% around the world are running with EternalBlue, in the UK it’s 0.82%.
How can organizations protect themselves?
There are many steps businesses can take to protect themselves from hackers. Businesses should make sure they have multiple layers of defense, including antivirus, firewall, intrusion detection, update their firmware and software on a regular basis, and implement proper usage access rights for their employees. Furthermore, businesses should assess the software they use, making sure the software they are using continues to receive security updates.
It is also extremely important for businesses to keep the human factor in mind when considering how to best secure their business. Humans make mistakes and hackers like to exploit human mistakes, so it is vital that businesses discuss security best practices with their employees.
Penetration testing is a great way for companies to see where their weaknesses lie, and what hackers could potentially exploit on and offline. Penetration testing should be done a few times a year, as hackers are always looking for and finding new ways to hack their way into businesses.
Finally, but equally as important, businesses should keep backups of their data. There are a range of different potential backup solutions from cloud storage to external hard drives, network device storage to USBs or flash drives. How many backups a business has is just as important as where they back up. Saving information to two locations, in the cloud and on a physical external hard drive, can help to keep information more secure. When using an external hard drive, it is important to disconnect and store them somewhere safe after the backing up process to keep the information protected from malware like ransomware, which can spread from computers to attached devices. Lastly, one of the most important working best practices is to enable any automatic backup option offered by most cloud storage services. This ensures that data is automatically backed up and secured removing any temptation to hit the ‘Remind me later’ button.
Jakub Kroustek is Threat Lab Team Lead at Avast
Why was this particular trojan so successful – what was so special about it? The attack was well prepared by its authors. NotPetya initially spread via the M.E.Doc accounting software when cybercriminals hacked the software’s update mechanism to spread NotPetya to systems when the software was updated. This was a…
Recent Posts
- ChatGPT-4.5 is here for Pro users now and Plus users next week, and I can’t wait to try it
- How to address Shadow IT challenges in the age of GenAI
- Groupon Promo Codes: 25% Off March 2025
- Your new favorite teacher might be this AI educator that never loses their patience
- Kia’s next EV is the affordable, long-range EV4 sedan
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010