More about the ExPetr malware, its targets and capabilities
Our analysis indicates that ExPetr/NotPetya has been designed with data destruction in mind. To launch this attack, its authors have carefully created a destructive malware disguised as ransomware. While some parts of this destructive malware still operate as original building blocks, meaning they might be mistaken for ransomware, their true purpose is destruction, not financial gain. Please find more information here, here and here.
A series of “ransomware” attacks targeting businesses in Ukraine, Russia, and the US in the summer of 2017. The victims’ files were encrypted and told they’d be returned once $300 in bitcoins was delivered. However, in reality, it was a wiper—the victims’ files couldn’t be decrypted even after the ransom was paid.