A new wave of the Petya ransomware has been affecting a significant number of organisations across a wide range of target industries. Multiple organizations within Ukraine, Spain, Netherlands, and the UK have been affected.
Petya is more dangerous and intrusive as its behaviour is to encrypt the Master File Tree (MFT) tables for NTFS partitions and overrides the Master Boot Record (MBR) with a custom bootloader to display a ransom note and prevents victims from booting up. In other words, Petya encrypts one’s entire hard-disk on the computer, rather than individual files and applications.
Petya spread via email spam with booby-trapped Office documents. The documents, once opened, will download and run the Petya installer and execute the SMB worm to spread to other computers.
Affected systems:
- Windows 10
- Windows 7
- Windows XP
- Windows Server 2016
- Windows Server 2012 and Window Server 2012 R2
- Window Server 2008 and Windows Server 2008 R2
How to protect from being attacked:
- Do not open Microsoft office attachments in emails from unknown senders
- Always verify with the sender (Call or send new email) before opening Microsoft office attachments sent from known senders.
- Make sure to update your Anti-virus software and Windows patches on your office workstations and home computers (Windows Operating system).
- Make sure all important personal data is backed up on your personal computers.
