All vulnerabilities
CRITICALSupply chainexploited in the wild

SC-MEDOC-NOTPETYA-2017

Software vendor · M.E.Doc (MEDoc) accounting software

Summary

On June 27, 2017 the NotPetya wiper spread through the software update mechanism of M.E.Doc, a Ukrainian tax-accounting product used by roughly 80% of the market. Russia's Sandworm group had hijacked M.E.Doc's update servers earlier in 2017 and used a backdoored update as patient zero, then propagated laterally using EternalBlue and Mimikatz. Masquerading as ransomware, NotPetya was designed for destruction rather than profit; it hit over 12,500 machines in Ukraine and spread to 64+ countries, causing billions in damage to firms such as Maersk, Merck and FedEx.

References

Related vulnerabilities

All Supply chain →