Skip to main content

Petya Is Not A Ransomware, It’s A “Wiper” — It’s Out To Destroy Your Data Forever


petya wiper not ransomware
Image: Comae
Petya malware, which is being seen as WannaCry’s obvious successor, isn’t a ransomware. It actually disguises itself as one to lure media coverage. Instead, it’s a wiper malware which destroys your data in such a manner that the possibilities of the
recovery of files are thin. Hence, even paying ransom won’t get your data back.
When security firms like Kaspersky, Symantec, and Avira reported about the Petya malware, they called it a ransomware. They had every reason to do so because of its activities like showing a ransom message which demanded $300 in Bitcoin. But, according to the latest development, it looks like this malware might not be a ransomware at all.
If you look at the definition of a ransomware–many of you would be already knowing that–it talks about a malware that holds your files for a ransom and unlocks them if you pay a hefty fee. On the contrary, Petya is a wiper–it doesn’t plan to give you the files back even if you pay the ransom.
The researchers from Comae Technologies and Kaspersky Lab have studied the malware deeply and independently arrived at the conclusion that Petya malware isn’t a ransomware, it’a wiper.

How is a ransomware different from a wiper? Is Petya wiper more dangerous?

As said above, a wiper isn’t interested in giving your data back, which is a totally different motive as compared to a ransomware. While a ransomware aims to make money, a wiper works with the aim of destruction in such a manner that the possibilities of the recovery of files in minimal.
This behavior is different from 2016 Petya malware where it was able to revert its changes. The 2017 Petya’s damage is irreversible, and it purposely overwrites the MBR section of the disk with the new bootloader.
petya wiper code not ransomware
Wiper code in Petya 2017 (Image: Comae)
Kaspersky Lab has said that Petya disguises itself as a ransomware and shows merely randomized data as the installation key. So, even the attacker can’t extract any decryption information from such data and the victim won’t be able to decrypt any disk using the key.
Moreover, the users infected with Petya wiper are shown an email address which was shut down by the email provider Posteo.
Comae has concluded that Petya pretends to be a ransomware to lure the media, which makes perfect sense after the amount of attention WannaCry got.
For further technical goodies, read these articles from Kaspersky and Comae.

Comments

Follow Us

WHAT'S HOT

How To Schedule Jobs in Linux | Cron and Crontab Commands

While using a computer system, often one faces the need to carry out certain repetitive jobs on a schedule. Instead of manually executing the requisite commands each and every single time, you can make things easier for yourself by using the Linux Cron utility and

The Decryption Key Of An Apple Security Chip Called Secure Enclave Has Been Leaked By A Hacker

Secure Enclave Processor (SEP) is a security chip that Apple started putting in iPhones since the release of iPhone 5S.

Poco F2 Pro 5G Officially Launched Globally With Snapdragon 865

After months of wait, Poco has officially launched Poco F2 Pro. The phone is a sequel to the Poco F1 which was a huge success for the company back in 2018. It is also the second Poco contender in 2020. In February, the Poco brand revealed a new phone lineup and launched Poco X2. The phone was priced at Rs 15,999 and featured similar specs of Redmi K30, a Xiaomi flagship that was launched back in 2018. The company has applied the same strategy for today’s launch. As we expected, Poco F2 Pro bundles all the specs of Redmi K30 Pro that Xiaomi launched last month. Poco F2 Pro Specifications, Availability and Price Unlike the Poco X2, the phone offers a circular camera at the back and a pop-up selfie camera at the front as opposed to the regular dual-hole punch cutout on the display of Poco X2. Poco F2 Pro comes with a 6.67-inch FHD+ AMOLED display with a 92.7% screen to body ratio. On top of that, the phone has an in-display fingerprint sensor to keep up with...

Zambia court rejects opposition bid to block Lungu’s inauguration

Zambia’s main opposition, United Party for National Development (UPND), said the Supreme Court had rejected its application to stop President Edgar Lungu’s inauguration, set for Tuesday. Keith Mweemba, a lawyer to the opposition leader, Hakainde Hichilema, disclosed this to newsmen in Lusaka on Monday. He said that the trial judge at the Lusaka High Court declined to grant the application on grounds that