PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

Petya Ransomware: What You Need to Know

Petya has affected more than 12,500 machines in Ukraine alone, and spread to another 64 countries, including Belgium, Brazil, Germany, Russia, and the US.

 & Angela Moscaritolo Managing Editor, Consumer Electronics

Our team tests, rates, and reviews more than 1,500 products each year to help you make better buying decisions and get more from technology.

Our Expert
LOOK INSIDE PC LABS HOW WE TEST
65 EXPERTS
43 YEARS
41,500+ REVIEWS

A global ransomware outbreak known as Petya has government agencies and private businesses around the globe scrambling to get their systems back online and recover their data.

The ransomware spread like wildfire on Tuesday, hitting organizations across Europe and the US. According to Microsoft, Petya has affected more than 12,500 machines in just the Ukraine, where the first infections were identified. Since then, it has spread to another 64 countries, including Belgium, Brazil, Germany, Russia, and the US.

The Petya outbreak comes after hundreds of thousands of PCs were attacked last month by ransomware known as WannaCry, which threw government agencies and private businesses around the globe into disarray. WannaCry resurfaced just last week, infecting the network at a Honda factory in Japan and traffic cameras in Australia.

Who has been affected?

The Petya ransomware has already taken offline several critical infrastructure institutions in Ukraine, according to Bogdan Botezatu, senior e-threat analyst at cybersecurity firm Bitdefender. Ukraine's state power distributor Ukrenergo was hit, along with several of the country's banks, and the Kiev Metro.

Beyond Ukraine, Petya has claimed a number of other high-profile victims, including: Chernobyl's radiation monitoring system, law firm DLA Piper, pharmaceutical company Merck, Danish shipping and energy company Maersk, UK-based advertising and public relations firm WPP, and Russian oil industry company Rosnoft.

McAfee Petya Map

McAfee released a map (which you can see above) showing the distribution of its clients that have detected the current known samples of Petya, with darker colors representing a greater number of infections. The map appears to suggest that the US has been harder hit than Ukraine, though Chief Research Officer at security firm F-Secure Mikko Hypponen said that might not technically be the case, since McAfee has "much better visibility" in the US than Ukraine.

What does it do?

The malware, which has similarities to WannaCry, encrypts the files on a user's system then demands victims pay $300 worth of bitcoin to recover access to their files.

"If you see this text, then your files are no longer accessible, because they have been encrypted," the message reads. "Perhaps you are busy looking for a way to recover your files, but don't waste your time. Nobody can recover your files without our decryption device."

The message goes on to "guarantee" victims will "safely and easily" recover all their files by submitting the payment. Petya operators have already received around 40 payments totaling $9,000, according to Bitdefender's Botezatu.

"If you're planning to pay the ransom, stop now," he warned. "You'll lose your data anyway, but you'll contribute in funding the development of new malware."

How it spreads

According to Microsoft, Petya "has worm capabilities, which allows it to move laterally across infected networks." This means its takes just one infected machine to affect an entire network, the company said.

This feature makes Petya more nefarious than other ransomware attacks, according to Rick Howard, Chief Security Officer at Palo Alto Networks.

"Ransomware attacks are very common, but they are rarely coupled with an exploit that allows the malware to spread as a network worm," he wrote in a blog post.

This version of Petya spreads via Windows Server Message Block (SMB) using an exploit tool known as EternalBlue, which exploits the vulnerability CVE-2017-0144 that was patched in security update MS17-010. WannaCry also exploited this vulnerability to spread to out-of-date machines. Petya also uses a second exploit for the vulnerability CVE-2017-0145 (also known as EternalRomance), which was also fixed by the aforementioned security update, Microsoft said.

How to protect yourself

Microsoft said those who have not yet installed security update MS17-010 (linked above) should do so as soon as possible.

"The WannaCry attacks in May 2017 demonstrated that many Windows systems had not been patched for this vulnerability," Palo Alto Networks's Howard wrote. "The spread of Petya using this vulnerability indicates that many organizations may still be vulnerable, despite the attention WannaCry received."

If you can't apply the patch right away, Microsoft recommends two workarounds to reduce your risk: disabling SMBv1 (instructions here) and consider adding a rule on your router or firewall to block incoming SMB traffic on port 445.

Organizations should also be sure to "create and maintain good back-ups so that if an infection occurs, you can restore your data," Howard wrote.

About Our Expert

Angela Moscaritolo

Angela Moscaritolo

Managing Editor, Consumer Electronics

My Experience

I'm PCMag's managing editor for consumer electronics, overseeing an experienced team of analysts covering smart home, home entertainment, wearables, fitness and health tech, and various other product categories. I have been with PCMag for more than 10 years, and in that time have written more than 6,000 articles and reviews for the site. I previously served as an analyst focused on smart home and wearable devices, and before that I was a reporter covering consumer tech news. I'm also a yoga instructor, and have been actively teaching group and private classes for nearly a decade. 

Prior to joining PCMag, I was a reporter for SC Magazine, focusing on hackers and computer security. I earned a BS in journalism from West Virginia University, and started my career writing for newspapers in New Jersey, Pennsylvania, and West Virginia.

The Technology I Use

My little Florida beach bungalow is brimming with smart home tech. I have a smart speaker or display in every room, allowing me to control other connected devices by voice. The Nest Hub on my bedside table lets me set wake-up alarms, control my smart light bulbs, and set the temperature on my smart thermostat. I use the Amazon Echo Show 8 on my kitchen counter to browse recipes, reorder protein powder, check the weather, and watch the news while I do dishes. 

Because I suffer from allergies, air purifiers are essential. My favorite model is the Dyson Purifier Cool TP07, which doubles as a fan and continuously sends indoor pollution data to its companion mobile app. 

My pitbull Bradley sheds, so a good robot vacuum is a must. I currently use a premium Ecovacs Deebot that can both vacuum and mop, empty its own dustbin, and wash its own mop cloth. 

For fitness, I like to mix up my routine with cycling, indoor rowing, running, and strength training in addition to yoga. I take classes on the Tonal 2 smart strength training machine, I row indoors on an Aviron machine, and track my beach runs with an Apple Watch while listening to music on my Apple AirPods Pro. On the weekends, I love riding e-bikes like the rugged, beach-friendly Aventon Aventure for fun and fitness.

My job involves a lot of virtual meetings, so a quality webcam, microphone, and ring light are important. I use the Jabra PanaCast 20 webcam, the Elgato Wave: 3 microphone, and a Yesker tripod ring light. 

As for my preferred phone platform, I'm an iPhone person, but I've also extensively used Android for product testing.

Read full bio