Malware spreading in recent outbreak is not ransomware, as “Petya” had been altered to wipe and destroy system memory, suggesting a nation state was behind it
Matt Suiche / Comae Technologies :
Context & Ripple Effects
The day before this analysis, researchers at Eset and Recorded Future had framed the outbreak as a Petya variant that harvests passwords and spreads via the NSA's EternalBlue exploit. Matt Suiche's memory-forensics work at Comae breaks that frame: the payment mechanism is intact-looking but the payload destroys system memory, meaning victims who pay get nothing back.
That reclassification matters because it changes who the attacker is presumed to be — profit-driven criminals versus a state willing to burn infrastructure under a ransomware disguise, a reading later borne out when the Russia-linked campaign was tied to an estimated $10B+ in damages, with Maersk forced into reinstalling 4,000 servers and 45,000 PCs.
First-order effects
- Affected organizations lose the standard ransomware playbook: since the malware wipes rather than encrypts, recovery means rebuilding from backups and clean images, not buying a decryption key.
- Security vendors and incident responders must reclassify active outbreaks mid-crisis, shifting customer guidance from 'isolate and negotiate' to full forensic containment.
Second-order effects
- The attackers themselves signal the cover story is thin — within a week the operators behind the outbreak empty their BTC wallet while asking for 100 BTC for a private key, an attempt to reset the ransomware narrative that few buyers find credible (the wallet-draining episode).
- Ransomware defense economics tilt further toward offline backups and network segmentation, since paying is now demonstrably not a recovery path even when a payment flow exists.
Third-order effects
- Destruction disguised as extortion becomes a repeatable state playbook: five years later Microsoft identifies [[a:974983|destructive malware targeting Ukrainian organizations that looks like ransomware but lacks any recovery mechanism]], echoing the same design.
- Attribution pressure builds toward treating ransomware-style attacks on critical infrastructure as potential state operations, raising the bar for how insurers, regulators, and victims respond to 'ransomware' incidents generally.
The trend: State-linked destructive attacks are increasingly dressed as ransomware, forcing defenders to treat every encryption event as a possible wiper until proven otherwise.