The NotPetya Cyberattack: A Paradigm Shift in Global Cyber Warfare
The landscape of digital threats has evolved from hobbyist virus writers distributing code on floppy disks to sophisticated, state-sponsored campaigns capable of crashing global commerce. The most devastating example of this shift is the NotPetya attack, a digital weapon that blurred the line between financial crime and geopolitical warfare.
- Nature of Attack: While it appeared to be ransomware, NotPetya was actually a “wiper” designed to destroy data without a way to recover it.
- Attribution: The US and UK governments attributed the attack to the Russian military, specifically the GRU’s Sandworm hacking group.
- Economic Impact: The attack caused an estimated $10 billion in worldwide economic losses.
- Propagation: It utilized the EternalBlue exploit to spread rapidly across Windows-based systems.
What Was NotPetya?
First appearing in June 2017, NotPetya was a variant of the Petya malware family. While the original Petya discovered in 2016 was a traditional cryptovirus, NotPetya operated differently. Although it demanded a Bitcoin payment from victims to decrypt their files, security researchers and governments identified it as a wiper because it lacked a legitimate decryption method. Its primary goal wasn’t profit; it was destruction.
The malware targeted Microsoft Windows-based systems by infecting the master boot record (MBR). Once inside, it encrypted the HDD or SSD file system table and triggered a fake CHKDSK (Check Disk) process after a system restart. This effectively prevented the computer from booting, locking users out of their systems entirely [3].
The Mechanism of Infection: EternalBlue
NotPetya’s devastating speed was fueled by the EternalBlue exploit [3]. This exploit, generally believed to have been developed by the U.S. National Security Agency (NSA), allowed the malware to propagate autonomously across networks. This was the same mechanism used earlier in 2017 by the WannaCry ransomware, making NotPetya a lethal evolution of existing cyber tools.
Global Chaos: The Case of Maersk
The attack primarily targeted Ukraine, but it quickly spiraled into a global crisis, affecting government, financial, and commercial websites in more than 60 countries [2].

One of the most prominent victims was A.P. Møller-Maersk, the world’s largest shipping conglomerate. On the afternoon of June 27, 2017, Maersk employees in Copenhagen began reporting laptops with red and black lettering. Some screens warned that the system was “repairing file system on C:,” while others displayed a surreal message: “oops, your important files are encrypted,” demanding $300 in bitcoin for their return [1].
Attribution and Geopolitical Fallout
In February 2018, the governments of the UK and US officially attributed NotPetya to a Russian military operation [2]. Specifically, the attack is blamed on the Sandworm hacking group, which operates within the GRU, Russia’s military intelligence organization [3].
The attack demonstrated the concept of “spillover” risk—the potential for offensive cyber operations to reach beyond intended targets and cause collateral damage to uninvolved states or even the perpetrator themselves. Reports suggest that NotPetya caused some level of self-harm to Russian companies, though the exact quantification of these domestic losses remains a gap in current scholarship [2].
The Evolution of Russian Cyber Tactics
NotPetya marked a turning point in how state actors conduct digital warfare. Since then, Russian cyber tactics have continued to evolve. Following the 2022 invasion of Ukraine, the GRU shifted its focus away from traditional phishing methods toward targeting “edge” devices, such as routers and firewalls, to gain network access [4].
Frequently Asked Questions
Was NotPetya actually ransomware?
No. While it used the guise of ransomware by demanding payment, it was a wiper. Because there was no way to decrypt the data, the payment demand was a ruse to hide the attack’s true destructive purpose [3].
How much did the attack cost globally?
NotPetya generated an estimated economic loss of $10 billion worldwide [2].
What is the “Sandworm” group?
Sandworm is a hacking group within the GRU, the Russian military intelligence organization, which has been identified by several governments and security researchers as the entity responsible for the NotPetya attacks [3].
Worth a look