Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Preventing Petya and Other Types of Ransomware current page
Link copied

Preventing Petya and Other Types of Ransomware

Aug 1, 2017
Author:
Russell Smith Bio Pic 2021 Square
Russell Smith
IT Consultant & Security MVP
Blog banner default
Preventing Petya and Other Types of Ransomware
Russell Smith Bio Pic 2021 Square
Russell Smith
IT Consultant & Security MVP

Preventing Petya and Other Types of Ransomware

The recent ransomware events have a few things in common – they target Windows operating systems and are largely preventable, but IT organizations have to remain diligent with applying patches.

For example, in March of this year, Microsoft patched a flaw in SMBv1, a legacy file-sharing protocol in Windows. Despite the availability of the update, two months later, the WannaCry virus affected tens of thousands of Windows devices around the globe. WannaCry exploited the SMB vulnerability previously patched by Microsoft, making it entirely preventable. And such was the magnitude of the event that Microsoft went out of its way to patch the now unsupported Windows XP and Windows 2003 Server, even though WannaCry didn’t target these operating systems.

Another global incident occurred at the end of June. Petya was an evolution of WannaCry—also exploiting the same SMBv1 vulnerability but adding worm capabilities to spread throughout a network. Although unlike WannaCry, it’s believed that Petya was designed to wipe out data and cause chaos, rather than hold the data ransom.

According to Kaspersky Labs, 95% percent of all devices infected by WannaCry were running Windows 7. Windows 10 devices were largely unaffected because of built-in mitigation technologies but could be vulnerable to new variants in the future. Additionally, a study by RiskSense showed that Windows 10 Threshold 2 (version 1511) is the last version of the OS vulnerable to the SMBv1 exploit, demonstrating the importance of updating.

If you want to apply Microsoft’s recommended security settings, the Group Policy Object (GPO) backups in the Security Compliance Toolkit can be used to quickly configure Window 10 and Windows Server 2016. The security baseline guide for Windows 10 version 1709 includes Group Policy templates that allow organizations to disable SMBv1. And if your organization doesn’t need SMBv1, Microsoft recommends you disable it.

The Windows 10 Fall Creators Update (version 1709) won’t include server component of SMBv1 if you perform a clean install. In an upgrade scenario, the SMBv1 server component will remain if it was previously available. And it’s worth noting that the Windows 10 Creators Update (version 1703) includes the SMB 1.0/CIFS File Sharing Support feature. Home and Pro editions will still include the SMBv1 client, but SMBv1 is being completely removed from Enterprise and Education.

But SMBv1 isn’t the only potentially vulnerable component in Windows. Petya uses a payload like the Mimikatz framework to steal credentials using PowerShell, enabling it to move laterally across the network. That’s not to say that PowerShell is dangerous and should be disabled. On the contrary, it is the most secure way to manage Windows.

Implementing Microsoft’s best practice advice can reduce the risk of hackers exploiting management tools. Join me for my on-demand webinar, Preventing Petya and Other Types of Ransomware, where I discuss the mitigations I mentioned above in more detail, and:

  • Removing administrative privileges to prevent ransomware attacks
  • Staying up-to-date with patching
  • Blocking SMB v1
  • Deploying Application Control
  • Managing macro security in Microsoft Office
Latest Posts
  • Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Jun 12, 2026 Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Blog
    7m
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
Related
  • Stop Attacks by Connecting Your Security Dots
    Dec 22, 2016 Stop Attacks by Connecting Your Security Dots
    Blog
    1m
  • Top VM Reports for Healthcare
    Feb 24, 2011 Top VM Reports for Healthcare
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.