Cybereason Blog | Cybersecurity News and Analysis

Cybereason Detects and Stops NotPetya Ransomware

Written by Lital Asher-Dotan | Jun 28, 2017 12:38:55 PM

NotPetya ransomware has affected hundreds of organizations across Europe and across the world.

Since we discovered the attack, our team has been quite busy. In addition to discovering a kill switch that stops NotPetya in it’s tracks we’ve also:

  • Built and issued an update to the Cybereason Sensor for Windows that detects and prevents NotPetya as well as other MBR-based ransomware
  • Built and issued a new version of Cybereason RansomFree 2.3.0.0 that detects and prevents NotPetya as well as other MBR-based ransomware

What’s unique about NotPetya?

NotPetya encrypts files only after the machine is rebooted - unlike most ransomware that encrypts files as soon as it executes. NotPetya spreads throughout the network, extracts admin credentials, and schedules a task to reboot the machine. As soon as a victim reboots their machine, NotPetya overwrites the Master Boot Record (MBR) with a malicious payload that encrypts the full disk.

How does Cybereason detect NotPetya?

Cybereason collects and analyzes behavioral data to identify if and when malicious activity occurs in an environment. In the case of NotPetya and other MBR-based ransomware, the solution detects malicious activity that attempts to affect the MBR. If a protected machine is infected with NotPetya, Cybereason will detect the activity and block NotPetya from encrypting any data. An infected machine will still be rebooted, but Cybereason will restore the original MBR to annihilate NotPetya’s ability to succeed.

 

Download RansomFree for free ransomware protection.