Open cardosec

Case 634ED5 · Famous breaches · L2 Practitioner

NotPetya

Practise as: Explain it · Deep dive
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. 27 June 2017: pushed via a trojanized update of M.E.Doc, Ukrainian tax software, a supply-chain attack
  2. Spread with EternalBlue/EternalRomance plus Mimikatz-stolen creds over PsExec and WMI, so patched hosts fell too
  3. Posed as ransomware but was a wiper: encrypted the MFT with no working recovery path
  4. Attributed to Russia's GRU (Sandworm); roughly $10B global damage, Maersk, Merck and FedEx/TNT hit hard
  5. Lessons: credential hygiene and segmentation matter as much as patching; a Ghana DC offline in a power cut saved Maersk's AD

If the interviewer pushes back

  • Why did insurers dispute NotPetya claims under war exclusions, and how did Merck's case end?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.