Petya Returns as Goldeneye Strikes Germany
released on 2016-12-13 @ 09:44:27 PM
A new variant of the notorious ransomware Petya is back - again - and with yet another James Bond reference for a name: Goldeneye. Presumably from the same author of Petya, which was first seen in December 2016, and the Petya-Mischa combo, which hit users back in July 2016, Janus Cybercrime Solution’s latest creation is another step in the evolution of their ransomware-as-a-service expansion.
Petya is a form of ransomware that overwrites the master boot record (MBR) in order to block access to both the user’s files and operating system. Safe Mode access is also disabled. Once Petya executes, the user’s machine will crash, restart, and show a skull-and-crossbones animation before displaying a ransom note asking for payment in bitcoin (BTC) in order to decrypt the system.