Cyber Alerts
New Petya Ransomware Variant Advisory
On June 27 2017, multiple organisations globally had reported of disruptions attributing to ransomware. Based on initial information received, a variant of Petya ransomware may be responsible for the incidents. National Cyber Coordination and Command Centre is currently monitoring closely for any signs of infection or propagation in Malaysia.
- First observed
- 27 Jun 2017
- Last checked
- 01 Aug 2026
- Evidence records
- 1
- Publication state
- Published
What happened?
Current assessment
On June 27 2017, multiple organisations globally had reported of disruptions attributing to ransomware. Based on initial information received, a variant of Petya ransomware may be responsible for the incidents. National Cyber Coordination and Command Centre is currently monitoring closely for any signs of infection or propagation in Malaysia.
Why it matters
Encrypt user files and demand ransom to decrypt the files for USD300 worth of Bitcoin.
Who is affected?
Affected products and groups
- Software: All Microsoft Windows Operating System
What should you do now?
Actions from official guidance
For technical teams
- We advise agencies to take the following actions: Official source
- Update your critical assets with the latest security patches and updates from Microsoft; Ensure your organisation is running an actively supported operating system that receives security updates; Block SMB ports (139, 445) from all accessible hosts at both endpoints, across VLANS as well as Internet and network gateway. If the SMB service is required, please ensure the patch (MS17-010) has been applied; Ensure that anti-virus/anti-malware signatures is up to date and functioning; If you receive an email with an unexpected attachment or link, verify with the sender BEFORE opening the attachment or clicking on the link; Warn your users not to open or click on unsolicited mails and links with/without attachments; Avoid enabling macros from email attachments. If a user opens the attachment and enables macros, embedded code will execute the malware on the machine. For enterprises or organisations, it may be best to block email messages with attachments from suspicious sources; Back up your important files and data to an external drive; Update your IPS and application layer firewall rules to monitor and detect any indicators of compromise; Update SNORT SMB signatures related to detect any SMB scan in your network. https://docs.emergingthreats.net/bin/view/Main/2024218. This signature can be used to detect all infected machines in a network. Once infected machines are identified, they need to be disconnected from the network and malware removal process should take place. Please make sure that your operating system is patched with the latest updates and patches prior to re-connecting to the network; System administrators with high level of access should avoid using their administrator accounts for email and web browsing; Change the password upon recovery of infected system; Use application whitelisting to help prevent malicious software and unapproved programs from running; Restrict users' ability (permissions) to install and run unwanted software applications, and apply the principle of "Least Privilege" to all systems and services; Have effective patch management that deploys security updates to endpoints and other critical systems within your infrastructure in a timely manner; Do not pay the ransom to the perpetrators; and For any incidents related to this attack, please report to NC4. Official source
Which sources support it?
Evidence and official sources
-
NACSA / NC4 Alerts and AdvisoriesOfficial sourceNew Petya Ransomware Variant Advisory
On June 27 2017, multiple organisations globally had reported of disruptions attributing to ransomware. Based on initial information received, a variant of Petya ransomware may be responsible for the incidents. National Cyber Coordination and Command Centre is currently monitoring closely for any signs of infection or propagation in Malaysia.
Published 27 Jun 2017 · Retrieved 01 Aug 2026