Petya Ransomware May Not Have Been About Making Money, Says Cisco's Talos

Advertisement
By Indo-Asian News Service | Updated: 29 June 2017 18:18 IST
Highlights
  • Petya malware is doubted to be more than just a money-making ransomware
  • Ransomware usually advertise multiple wallets and emails to collect money
  • With Petya, the wallet and email were blocked almost immediately

Petya, the malware that has affected companies and institutions around the world may not have been ransomware - its purpose could have been political, believes a leading cyber-security expert.

The virus was "unusual" as it had only one wallet and one email linked to it and "may not have been about making money", according to Craig Williams, Senior Technical Leader at Cisco's cyber-security division Talos, which has been tracking the virus, called Petya, Nyetya, NotPetya, and ExPetr.

Ransomware usually advertise multiple wallets and emails so that money can be collected from the companies whose data has been affected, said Williams.

Advertisement

"Looks like someone has been trying to design something that looks like ransomware," he added.

Advertisement

In the case of Petya aka Nyetya, with the wallet and email blocked almost immediately, there was no way the affected companies could make payments, even if they wanted to, he added.

The fact that the attack seemed to have been aimed at Ukraine and came ahead of the country's Constitution Day, pointed the needle of suspicion at a political purpose, Williams said, adding, however, that it could not be said with certainty that it was a state-sponsored attack.

Advertisement

He said the fact that the virus had affected other countries and companies outside Ukraine could have been a case of "collateral damage", with the networks of companies that did business with that country becoming infected.

"We believe that's what's happening," he said.

The new cyber-attack began massively affecting dozens of companies and institutions in the world, beginning with Russia and Ukraine on Tuesday, and spreading to Asia, Australia, and the US.

Advertisement

According to Williams, Petya aka Nyetya is the first virus to use three lateral vectors - Eternal Blue (same as WannaCry) and PSExec and WMI - both legitimate Windows administrator tools.

WannaCry had affected 200,000 people in 150 countries in May, encrypting data on infected computers and asking for a ransom to recover them.

However, WannaCry was "not much of a financial success", said Williams, as it only made about $30,000 (roughly Rs. 19.3 lakhs) in the first week.

Such attacks were soon going to be common "as more and more people look to make money from ransomware", warned Steve Martino, Cisco's Chief of Information Security, adding that companies need to be proactive in protecting their networks.

India, meanwhile, has largely remained insulated so far from the latest attack.

The Shipping Ministry on Wednesday said operations at one of the container terminals at Mumbai's Jawaharlal Nehru Port Trust (JNPT) were impacted due to a global cyber-attack.

According to the Ministry, a private terminal operator at the JNPT was taking steps to address the issue. It was anticipated that there could be bunching of in-bound and out-bound container cargos.

"We have been taking proactive steps... we have sent out advisories (on the cyber-attack and the malware)... India is not much affected at this stage," IT Minister Ravi Shankar Prasad said at an event in New Delhi.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 70 Launched With Snapdragon 7 Gen 4 SoC, Slim 5.99mm Profile
  2. Lava Agni 4 Price Range, Features Leaked; Will Launch in These Colourways
  3. Moto G67 Power 5G Launched in India With 7,000mAh Battery: See Price
  4. Samsung Galaxy S26 Ultra Spotted in Leaked Renders With Rounder Corners
  5. Moto G Play (2026), Moto G (2026) With Dimensity 6300 SoC Launched
  6. Southern Taurid Meteor Shower 2025 Promises Bright Fireballs in a Rare Swarm Year
  7. Apple's Low-Cost MacBook Launch Timeline, Price Leaked Ahead of Debut
  8. OnePlus Ace 6 Pro Max Configurations Leaked; May Feature Up to 16GB of RAM
  9. WhatsApp's Apple Watch App Is Finally Out: Check Features, Compatibility
  10. How Hot Was the Universe 7 Billion Years Ago? Scientists Now Have an Answer
  1. Motorola Edge 70 Launched With Snapdragon 7 Gen 4 Chipset, Slim 5.99mm Profile: Price, Specifications
  2. Researchers Unveil How Atomic Entanglement Enhances Light Bursts
  3. Lava Agni 4 Confirmed to Launch in Two Colourways; Tipster Leaks Price Range, Key Features
  4. Google Proposes Play Store Reforms in Settlement With Fortnite Maker Epic Games
  5. Scientists Recreate Cosmic ‘Fireballs’ in Lab to Solve Mystery of Missing Gamma Rays
  6. Realme UI 7.0 Launched With Light Glass Design, AI Notify Brief and AI Gaming Coach: See Eligible Phones, Beta Release Schedule
  7. iOS 26.2 Beta 1 Rolled Out to Developers With Enhanced Safety Alerts, Reminder Alarms
  8. Samsung Galaxy S26 Ultra Spotted in Leaked Design Renders That Hint at Rounder Corners
  9. Call of Duty: Black Ops 7 PC Specifications, Preloading Times Revealed; Activision Confirms Handheld Support
  10. Silicon Carbide-Based Motor Drive Enables a Smaller, Lighter Electric Aircraft Engine
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.