LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0368: NotPetya

NotPetya is malware that was used by Sandworm Team in a worldwide attack starting on June 27, 2017. While NotPetya appears as a form of ransomware, its main purpose was to destroy data and disk structures on compromised systems; the attackers never intended to make the encrypted data recoverable. As such, NotPetya may be more appropriately thought of as a form of wiper malware. NotPetya contains worm-like features to spread itself across a computer network using the SMBv1 exploits EternalBlue and EternalRomance.[1][2][3][4]

EnterpriseS0368MalwareObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

NotPetya matters because ATT&CK describes it as destructive Windows malware that looked like ransomware but was intended to destroy data and disk structures, with worm-like spread using SMBv1 exploits. For leaders, the lesson is not “ransomware payment readiness”; it is whether the business can contain rapid Windows lateral movement and restore operations when encrypted or damaged systems are not recoverable by design.

Executive priority

Treat this as a resilience and segmentation test case. Executives should ask whether critical Windows environments, including any IT systems connected to operational or ICS environments, can withstand SMB-based propagation, credential abuse, remote execution, forced reboots, and destructive impact. Priority decisions should focus on patch/vulnerability governance for remote services, backup and restore confidence, network segmentation, privileged account exposure, and incident response authority to isolate systems quickly. The ICS relationship to Loss of Productivity and Revenue makes this especially relevant where IT disruption can halt operations.

Technical view

ATT&CK provides no official detection text for S0368, so validation should be relationship-driven. SOC and IR teams should map coverage across Windows behaviors associated with NotPetya: LSASS credential access, SMB and admin share lateral movement, exploitation of remote services, WMI, scheduled tasks, rundll32 execution, service execution, file and security software discovery, Windows event log clearing, data encryption for impact, and system shutdown/reboot. The key defensive question is whether telemetry links these events into a fast-moving propagation-and-impact chain rather than treating each event as an isolated alert.

Likely telemetry

  • Windows process creation and command-line telemetry for rundll32.exe, schtasks, service control activity, WMI execution, shutdown or reboot commands, and event log clearing utilities
  • Windows Security, System, and Application event logs, including evidence of log clearing where retained centrally
  • Endpoint detection telemetry for LSASS access, credential material access attempts, discovery activity, and destructive file or disk behavior
  • SMB and Windows admin share access records, including lateral connections between peer systems
  • Network telemetry for SMBv1 or SMB-based movement and remote service exploitation indicators

Detection direction

  • Build correlation around rapid internal spread: SMB/admin share access, remote service use, WMI or service execution, and tool/file transfer between Windows hosts.
  • Prioritize detections where credential access or local account abuse is followed by lateral movement and impact activity.
  • Validate alerting for Windows event log clearing, but assume local logs may be impaired; confirm centralized log forwarding and retention.
  • Tune for administrative false positives by baselining legitimate WMI, scheduled task, service control, and admin share usage, then alert on unusual source hosts, timing, scale, or target sets.
  • Use relationship context to include impact-stage monitoring for encryption-like activity and shutdown/reboot events, not only initial execution.

Mitigation priorities

  • First, reduce propagation paths: remove or tightly control SMBv1 exposure and prioritize patching of remotely exploitable services referenced by the ATT&CK description and relationships.
  • Second, constrain lateral movement: limit local administrator reuse, monitor and restrict admin shares, and enforce least privilege for local and service accounts.
  • Third, harden execution pathways commonly abused on Windows, including WMI, scheduled tasks, service execution, and rundll32 where business-appropriate.
  • Fourth, protect evidence and recovery: forward Windows logs centrally, protect backups from endpoint compromise, and regularly test restoration of business-critical Windows systems.
  • Fifth, segment critical operational or ICS-connected environments so IT malware propagation is less likely to create productivity or revenue loss.
Additional notes and limits

The supplied object identifies NotPetya as Windows malware used by Sandworm Team in a worldwide attack beginning June 27, 2017, with destructive/wiper intent and worm-like SMBv1 propagation using EternalBlue and EternalRomance. Relationship context expands the defensive map to credential access, lateral movement, execution, discovery, defense impairment, and impact techniques, plus ICS impact relationships. This take uses those relationships to frame practical validation priorities without asserting current activity or local exposure.

ATT&CK does not provide official detection guidance for this object, and the object itself lists tactics as not specified. Several related technique records include broad platform lists, but the malware object platform is Windows; environment-specific validation is required before assuming relevance to non-Windows assets, cloud assets, or ICS systems. Local telemetry quality, segmentation, patch status, backup architecture, and administrative practices determine actual risk and coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

NotPetya

NotPetya is malware that was used by Sandworm Team in a worldwide attack starting on June 27, 2017. While NotPetya appears as a form of ransomware, its main purpose was to destroy data and disk structures on compromised systems; the attackers never intended to make the encrypted data recoverable. As such, NotPetya may be more appropriately thought of as a form of wiper malware. NotPetya contains worm-like features to spread itself across a computer network using the SMBv1 exploits EternalBlue and EternalRomance.[1][2][3][4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

14 rows
DomainIDNameRelationship / procedure
EnterpriseT1569.002Service ExecutionSub-technique

NotPetya can use PsExec to help propagate itself across a network.[1][2]

EnterpriseT1053.005Scheduled TaskSub-technique

NotPetya creates a task to reboot the system one hour after infection.[1]

EnterpriseT1021.002SMB/Windows Admin SharesSub-technique

NotPetya can use PsExec, which interacts with the ADMIN$ network share to execute commands on remote systems.[1][2][5]

EnterpriseT1685.005Clear Windows Event LogsSub-technique

NotPetya uses wevtutil to clear the Windows event logs.[1][4]

EnterpriseT1518.001Security Software DiscoverySub-technique

NotPetya determines if specific antivirus programs are running on an infected host machine.[4]

EnterpriseT1047Windows Management Instrumentation

NotPetya can use wmic to help propagate itself across a network.[1][2]

EnterpriseT1210Exploitation of Remote Services

NotPetya can use two exploits in SMBv1, EternalBlue and EternalRomance, to spread itself to other remote systems on the network.[1][2][4]

EnterpriseT1083File and Directory Discovery

NotPetya searches for files ending with dozens of different file extensions prior to encryption.[4]

EnterpriseT1003.001LSASS MemorySub-technique

NotPetya contains a modified version of Mimikatz to help gather credentials that are later used for lateral movement.[1][2][6]

EnterpriseT1529System Shutdown/Reboot

NotPetya will reboot the system one hour after infection.[1][4]

EnterpriseT1486Data Encrypted for Impact

NotPetya encrypts user files and disk structures like the MBR with 2048-bit RSA.[1][2][4]

EnterpriseT1036Masquerading

NotPetya drops PsExec with the filename dllhost.dat.[1]

EnterpriseT1218.011Rundll32Sub-technique

NotPetya uses rundll32.exe to install itself on remote systems when accessed via PsExec or wmic.[1]

EnterpriseT1078.003Local AccountsSub-technique

NotPetya can use valid credentials with PsExec or wmic to spread itself to remote systems.[1][2]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0034: Sandworm Team

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.[1][2] This group has been active since at least 2009.[3][4][5][6]

In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.[1][2] Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.[7]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.0
Created
Modified
Raw hash
138515a612808a98...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.0Current bundle138515a61280…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  2. [2]
    US-CERT NotPetya 2017

    US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.

    Open source URL
  3. [3]
    ESET Telebots June 2017

    Cherepanov, A.. (2017, June 30). TeleBots are back: Supply chain attacks against Ukraine. Retrieved June 11, 2020.

    Open source URL
  4. [4]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  5. [5]
    PsExec Russinovich

    Russinovich, M. (2004, June 28). PsExec. Retrieved December 17, 2015.

  6. [6]
    NCSC Joint Report Public Tools

    The Australian Cyber Security Centre (ACSC), the Canadian Centre for Cyber Security (CCCS), the New Zealand National Cyber Security Centre (NZ NCSC), CERT New Zealand, the UK National Cyber Security Centre (UK NCSC) and the US National Cybersecurity and Communications Integration Center (NCCIC). (2018, October 11). Joint report on publicly available hacking tools. Retrieved March 11, 2019.

    Open source URL
  7. [7]
    NCSC Sandworm Feb 2020

    NCSC. (2020, February 20). NCSC supports US advisory regarding GRU intrusion set Sandworm. Retrieved June 10, 2020.

    Open source URL
  8. [8]
    UK NCSC Olympic Attacks October 2020

    UK NCSC. (2020, October 19). UK exposes series of Russian cyber attacks against Olympic and Paralympic Games . Retrieved November 30, 2020.

    Open source URL
  9. [9]
    Secureworks IRON VIKING

    Secureworks. (2020, May 1). IRON VIKING Threat Profile. Retrieved June 10, 2020.

    Open source URL
  10. [10]
    Trend Micro Cyclops Blink March 2022

    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

    Open source URL
  11. [11]
    mandiant_apt44_unearthing_sandworm

    Roncone, G. et al. (n.d.). APT44: Unearthing Sandworm. Retrieved July 11, 2024.

    Open source URL
  12. [12]
    Diskcoder.C

    (Citation: ESET Telebots June 2017)

  13. [13]
    Diskcoder.C

    (Citation: ESET Telebots June 2017)

  14. [14]
    Diskcoder.C

    (Citation: ESET Telebots June 2017)

  15. [15]
    ESET Telebots June 2017

    Cherepanov, A.. (2017, June 30). TeleBots are back: Supply chain attacks against Ukraine. Retrieved June 11, 2020.

    Open source URL
  16. [16]
    ESET Telebots June 2017

    Cherepanov, A.. (2017, June 30). TeleBots are back: Supply chain attacks against Ukraine. Retrieved June 11, 2020.

    Open source URL
  17. [17]
    ExPetr

    (Citation: ESET Telebots June 2017)

  18. [18]
    ExPetr

    (Citation: ESET Telebots June 2017)

  19. [19]
    ExPetr

    (Citation: ESET Telebots June 2017)

  20. [20]
    GoldenEye

    (Citation: Talos Nyetya June 2017)

  21. [21]
    GoldenEye

    (Citation: Talos Nyetya June 2017)

  22. [22]
    GoldenEye

    (Citation: Talos Nyetya June 2017)

  23. [23]
    Nyetya

    (Citation: Talos Nyetya June 2017)

  24. [24]
    Nyetya

    (Citation: Talos Nyetya June 2017)

  25. [25]
    Nyetya

    (Citation: Talos Nyetya June 2017)

  26. [26]
    Petrwrap

    (Citation: Talos Nyetya June 2017)(Citation: ESET Telebots June 2017)

  27. [27]
    Petrwrap

    (Citation: Talos Nyetya June 2017)(Citation: ESET Telebots June 2017)

  28. [28]
    Petrwrap

    (Citation: Talos Nyetya June 2017)(Citation: ESET Telebots June 2017)

  29. [29]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  30. [30]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  31. [31]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  32. [32]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  33. [33]
    US-CERT NotPetya 2017

    US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.

    Open source URL
  34. [34]
    US-CERT NotPetya 2017

    US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.

    Open source URL
  35. [35]
    mitre-attackS0368
    Open source URL
  36. [36]
    mitre-attackS0368
    Open source URL
  37. [37]
    mitre-attackS0368
    Open source URL
  38. [38]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  39. [39]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  40. [40]
    US-CERT NotPetya 2017

    US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.

    Open source URL
  41. [41]
    US-CERT NotPetya 2017

    US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.

    Open source URL
  42. [42]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  43. [43]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  44. [44]
    PsExec Russinovich

    Russinovich, M. (2004, June 28). PsExec. Retrieved December 17, 2015.

  45. [45]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  46. [46]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  47. [47]
    US-CERT NotPetya 2017

    US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.

    Open source URL
  48. [48]
    US-CERT NotPetya 2017

    US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.

    Open source URL
  49. [49]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  50. [50]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  51. [51]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  52. [52]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  53. [53]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  54. [54]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  55. [55]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  56. [56]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  57. [57]
    US-CERT NotPetya 2017

    US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.

    Open source URL
  58. [58]
    US-CERT NotPetya 2017

    US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.

    Open source URL
  59. [59]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  60. [60]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  61. [61]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  62. [62]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  63. [63]
    US-CERT NotPetya 2017

    US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.

    Open source URL
  64. [64]
    US-CERT NotPetya 2017

    US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.

    Open source URL
  65. [65]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  66. [66]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  67. [67]
    NCSC Joint Report Public Tools

    The Australian Cyber Security Centre (ACSC), the Canadian Centre for Cyber Security (CCCS), the New Zealand National Cyber Security Centre (NZ NCSC), CERT New Zealand, the UK National Cyber Security Centre (UK NCSC) and the US National Cybersecurity and Communications Integration Center (NCCIC). (2018, October 11). Joint report on publicly available hacking tools. Retrieved March 11, 2019.

    Open source URL
  68. [68]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  69. [69]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  70. [70]
    US-CERT NotPetya 2017

    US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.

    Open source URL
  71. [71]
    US-CERT NotPetya 2017

    US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.

    Open source URL
  72. [72]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  73. [73]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  74. [74]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  75. [75]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  76. [76]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  77. [77]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  78. [78]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  79. [79]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  80. [80]
    US-CERT NotPetya 2017

    US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.

    Open source URL
  81. [81]
    US-CERT NotPetya 2017

    US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.

    Open source URL
  82. [82]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  83. [83]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  84. [84]
    NCSC Sandworm Feb 2020

    NCSC. (2020, February 20). NCSC supports US advisory regarding GRU intrusion set Sandworm. Retrieved June 10, 2020.

    Open source URL
  85. [85]
    Secureworks IRON VIKING

    Secureworks. (2020, May 1). IRON VIKING Threat Profile. Retrieved June 10, 2020.

    Open source URL
  86. [86]
    Trend Micro Cyclops Blink March 2022

    Haquebord, F. et al. (2022, March 17). Cyclops Blink Sets Sights on Asus Routers. Retrieved March 17, 2022.

    Open source URL
  87. [87]
    UK NCSC Olympic Attacks October 2020

    UK NCSC. (2020, October 19). UK exposes series of Russian cyber attacks against Olympic and Paralympic Games . Retrieved November 30, 2020.

    Open source URL
  88. [88]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  89. [89]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  90. [90]
    mandiant_apt44_unearthing_sandworm

    Roncone, G. et al. (n.d.). APT44: Unearthing Sandworm. Retrieved July 11, 2024.

    Open source URL
  91. [91]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  92. [92]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  93. [93]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  94. [94]
    US-CERT NotPetya 2017

    US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.