A new strain of the Petya ransomware started propagating on June 27, 2017, infecting many organizations. Similar to Wannacry, Petya uses the Eternal Blue exploit.
After thousands of infections, the new Petya ransomware has run into its first major problem, as a German email provider has blocked the email account the virus was using to manage ransom demands. Victims should be advised not to pay into the wallet, since it’s unlikely the attackers can successfully decrypt systems at this point.
The problem is caused in part by Petya’s unorthodox method for collecting ransom payments. Most ransomware programs create a unique wallet for each infection, making it easy to know which victim is responsible for each payment. But Petya broke with that practice, asking every victim to send their $300 payment to the same single Bitcoin wallet, then send an email to wowsmith123456@posteo.net with a unique identifier to confirm payment and receive the decryption keys.
But in the wake of today’s globe-spanning infections, Posteo announced today that all account access to the “wowsmith” address have been blocked, making it impossible for the group to read or respond to any messages sent to the address.
What is Petya?
Petya has been in existence since 2016. It differs from typical ransomware as it doesn’t just encrypt files, it also overwrites and encrypts the master boot record (MBR).
In this latest attack, the following ransom note is displayed on infected machines, demanding that $300 in bitcoins be paid to recover files:
How does Petya spread and infect computers?
Petya propagates itself by exploiting the MS17-010 vulnerability, also known as Eternal Blue. Symantec continues to investigate other possible methods of propagation.
Who is impacted?
At time of writing, Petya is primarily impacting organizations in Europe.
Is this a targeted attack?
It’s unclear at this time, however, previous strains of Petya have been used in targeted attacks against organizations.



