Still crying over WannaCry, Petya and Goldeneye?
Summary
This blueAPACHE post reports: Even as organisations continue to cope with last month’s wave of ransomware attacks linked to WannaCry, on Tuesday, the world woke up to yet another global ransomware outbreak. Victims of the latest Petya ransomware include the Ukrainian government, the Chernobyl nuclear radiation monitoring system, U.S. It concerns emPOWER Security, Managed Detection & Response, Offsite Backup as a Service. Published in 2017. Figures, product names and event details reflect that time; for current information see the linked service pages.
Key facts
| Label | Value |
|---|---|
| Publication year | 2017 |
| Services referenced | emPOWER Security, Managed Detection & Response, Offsite Backup as a Service |
| Topic | Still crying over WannaCry, Petya and Goldeneye? |
Article
Even as organisations continue to cope with last month’s wave of ransomware attacks linked to WannaCry, on Tuesday, the world woke up to yet another global ransomware outbreak. Victims of the latest Petya ransomware include the Ukrainian government, the Chernobyl nuclear radiation monitoring system, U.S. pharmaceutical company Merck, Russian steel and mining firms and many others. Similar to WannaCry, Petya exploits the Windows SMBv1 vulnerability on unpatched computers. However, unlike WannaCry, which spread through email phishing campaigns, Petya is more traditional – the initial infection vector is associated with a software update for a Ukrainian tax accounting program – and has the capacity to spread rapidly throughout the network, infecting even those computers that have already been patched. Now, more than ever before, it is imperative that organisations are able to detect and respond to security events in a prompt manner. There is no substitute for good defences – they are a must. But even with the most advanced security measures there are limitations. It doesn’t matter how good your firewalls are, or how good your Intrusion Detection / Prevention System (IDS/IPS) is – you will be compromised at some point. It is understanding your security limitations, and preparing for them, that makes the difference in whether or not you can survive a cyberattack. So what can you do to protect yourself?
- Vulnerability Scanning – Keep yourself up-to-date with known areas of weakness in your systems. One of the major concerns with such attacks is that many organisations do not know they have been infected until it is far, far too late. The first indication they receive is when critical files and data are already unavailable and being held hostage. But it does not have to be that way. Attacks such as these are rarely ‘quiet’. They tend to be loud and noisy if you know where to look and what to look for. Traditionally, the real time analysis of system, server and application logs has been time consuming, involved and difficult. Logs were only looked at for after-event analysis. But to stay ahead of security incidents, organisations need a way of identifying what is occurring, and where it is occurring, in real time. This is where Security Incident and Event Monitoring (SIEM) can help. A SIEM platform can correlate and analyse security event data from across your cloud and on-premises environments in real time. This helps identify the source of compromise, contain it by isolating the infected systems and then implement mitigating actions – all in a timely manner that can limit damage.
- Patching – Stay on top of patch management to limit attack vectors Continuing to run critical services on an unsupported or unpatched system carries an extreme risk. Without regular security patches and updates, your systems become a playground for hackers who are constantly on the lookout for exactly such vulnerabilities to exploit.
- Backups – Maintain regular and frequent backups of al critical data and systems When all else fails, nothing can take the edge off a ransomware attack than knowing that all your critical systems and data are securely backed up and can be restored. Ideally your data backups should be maintained on external devices and stored offline and offsite. As a final note, according to reports, the email address that was being used to communicate with Petya victims has now been suspended, which means that even when the ransom is paid, there is no way to receive the decryption keys and retrieve files. There has been no impact of this outbreak on blueAPACHE clients. If you have concerns or want to improve your organisation’s security posture, contact the blueAPACHE security team. Our security consultants can assess your organisation’s level of exposure to phishing attacks and conduct workshops to educate your staff.
Related
- emPOWER Security
- emPOWER Security (pillar)
- Managed Detection & Response
- Offsite Backup as a Service
- emPOWER Cloud (pillar)
Frequently asked questions
Which organisations does the article name as victims of the Petya ransomware outbreak?
The article names the Ukrainian government, the Chernobyl nuclear radiation monitoring system, US pharmaceutical company Merck, and Russian steel and mining firms among Petya's victims.
How did Petya's initial infection method differ from WannaCry's, according to the article?
The article says Petya's initial infection vector was a compromised software update for a Ukrainian tax accounting program, whereas WannaCry spread through email phishing campaigns; both then exploited the Windows SMBv1 vulnerability to spread.
What three protective measures does the article recommend against ransomware?
The article recommends vulnerability scanning to stay aware of system weaknesses, patch management to limit attack vectors, and maintaining regular, offline and offsite backups of critical data and systems.
What does the article say happened to the Petya ransom payment channel?
The article says reports indicated the email address used to communicate with Petya victims was suspended, meaning even victims who paid the ransom had no way to receive decryption keys.
Is the information in this post still current?
No. It reports the 2017 WannaCry and Petya ransomware outbreaks; for blueAPACHE's current ransomware and incident response guidance, see the emPOWER Security pillar page rather than this post.
Source
https://www.blueapache.com/blog/still-crying-over-wannacry-petya-and-goldeneye/
Knowledge Base
What is the blueAPACHE blog post 'Still crying over WannaCry, Petya and Goldeneye?' about?
The post discusses the Petya ransomware outbreak that hit organisations on a Tuesday shortly after the WannaCry ransomware wave, and offers advice on how organisations can protect themselves from such attacks.
When was this blueAPACHE article published?
The article was written by blueAPACHE and dated June 29, 2017, with a read time of about 4 minutes.
Who were the victims of the Petya ransomware outbreak mentioned in the article?
Victims included the Ukrainian government, the Chernobyl nuclear radiation monitoring system, U.S. pharmaceutical company Merck, Russian steel and mining firms, and many others.
How did Petya's method of spreading differ from WannaCry's?
Like WannaCry, Petya exploits the Windows SMBv1 vulnerability on unpatched computers, but unlike WannaCry, which spread through email phishing campaigns, Petya's initial infection vector was associated with a software update for a Ukrainian tax accounting program, and it could spread rapidly throughout a network, infecting even already-patched computers.
What three protective measures does blueAPACHE recommend in this article to guard against ransomware attacks?
The article recommends: 1) Vulnerability Scanning to stay up-to-date with known weaknesses in systems; 2) Patching to keep systems updated and limit attack vectors; and 3) Backups, maintaining regular and frequent backups of all critical data and systems, ideally on external devices stored offline and offsite.
What role does SIEM play in detecting ransomware attacks according to the article?
A Security Incident and Event Monitoring (SIEM) platform can correlate and analyse security event data from cloud and on-premises environments in real time, helping to identify the source of compromise, contain it by isolating infected systems, and implement mitigating actions in a timely manner to limit damage.
What happened to the ransom payment process for Petya victims, according to the article?
According to reports cited in the article, the email address used to communicate with Petya victims was suspended, meaning that even if victims paid the ransom, there was no way to receive the decryption keys and retrieve their files.
Were any blueAPACHE clients affected by the Petya ransomware outbreak?
The article states there was no impact of the Petya outbreak on blueAPACHE clients.
What can organisations do if they want to improve their security posture after reading this article?
The article invites readers with concerns or who want to improve their organisation's security posture to contact the blueAPACHE security team, noting that blueAPACHE's security consultants can assess an organisation's level of exposure to phishing attacks and conduct workshops to educate staff.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bdfb153d68a8eeb6ab7_Petya-2.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701b59b153d68a8eeb0e36_BBanner-1-Windows-10-is-out.-AI-is-in.-.avif
You’ve Invest in Security. So Why Are Breaches Still Happening?
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb807b7741bf53e298a_BBanner-1-Windows-10-is-out.-AI-is-in.-8.avif
EOFY 2026: The Reset Is Done – Now It’s About Getting Ahead
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d0_BBanner-2-When-support-ends-risk-begins-4.avif
Why Every Business Needs AI Guardrails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d7_BBanner-2-When-support-ends-risk-begins-3.avif
Ransomware Incident Response: Why Paying the Ransom Is a Failure of Preparation
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb707b7741bf53e297d_BBanner-2-When-support-ends-risk-begins-1.avif
The 7 Cyber Truths Boards Must Act On In 2026
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29f9_BBanner-1-Windows-10-is-out.-AI-is-in.-7.avif
Reflecting on an Outstanding 2025 – Thank You for Your Partnership
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e2a0c_Procurement-Portal.avif
The blueAPACHE e-Store: IT purchasing made simple
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29ec_BBanner-1-Windows-10-is-out.-AI-is-in.-5.avif
Building Our Cyber Safe Culture: A Practical Guide for CSAM 2025
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.