Skip to content
Security Notes

NotPetya and Maersk: rebuilding from one surviving domain controller

By Elias Lankinen12 min read

I have everything I need: the definitive Wired account, primary technical analyses from Kaspersky and ESET, official UK and US attribution statements, and four verified images. Writing the post now.

The afternoon the world's biggest shipping company went dark

It was a warm, sunny afternoon in Copenhagen on 27 June 2017 when the world's largest container shipping company began to lose its mind. At the headquarters of A.P. Møller-Maersk on the harbour's edge, an IT administrator was preparing a routine software update for the firm's roughly 80,000 employees when his computer spontaneously rebooted. He looked up, and, as he told Wired's Andy Greenberg, watched every other screen in the open-plan office blink out in sequence: "black, black, black, black black black black." Within half an hour, staff were sprinting down hallways yelling at colleagues to unplug machines, vaulting over locked key-card gates that the malware had frozen, and pulling computers out of the walls mid-meeting. It took Maersk's IT team more than two panicky hours just to disconnect the company's global network. By then it was too late. A firm responsible for 76 port terminals and nearly 800 vessels, carrying close to a fifth of the entire world's shipping capacity, was dead in the water. What almost no one in that building understood yet was that the code eating their network had not been aimed at them at all. It was a weapon built for a war in another country, and it had just escaped.

Source: Slawos, via Wikimedia Commons (CC BY-SA 3.0)
Source: Slawos, via Wikimedia Commons (CC BY-SA 3.0)

A weapon built for Ukraine

The malware was called NotPetya, and its origin was almost absurdly mundane: a family-run Ukrainian software company called Linkos Group, in a gritty corner of Kyiv. Linkos makes M.E.Doc, an accounting and tax-filing program that is roughly Ukraine's equivalent of TurboTax. Nearly anyone who files taxes or does business in the country uses it; by some counts it was installed on the machines of around 90 percent of Ukraine's domestic firms. That ubiquity made it the perfect delivery vehicle for a supply-chain attack: instead of breaking into thousands of targets one by one, you compromise a single trusted supplier that pushes software to all of them at once. Sometime in the spring of 2017, hackers quietly took over M.E.Doc's update servers. According to security firm ESET's analysis, published on 30 June 2017, they planted a hidden backdoor and then, on 27 June, used the update mechanism to push out a malicious "update" that installed itself automatically, with no user interaction required. From that beachhead, the code detonated across Ukraine on the eve of the country's Constitution Day. The attackers were later identified as Sandworm, a unit of Russia's military intelligence agency, the GRU. Ukraine had by then spent more than three years as what one researcher called a scorched-earth testing ground for Russian cyberwar, including the first confirmed blackouts ever caused by hackers, in 2015 and 2016. NotPetya was the escalation. On the day it hit, it struck at least four hospitals in Kyiv, six power companies, two airports, more than 22 banks, and card payment systems across the country. One senior official estimated that 10 percent of all computers in Ukraine were wiped. Even the radiation monitoring systems at the decommissioned Chernobyl plant went down. Maersk was collateral. The company's entire global infection appears to have started from a single computer in its office in Odessa, where a finance staffer had asked IT to install M.E.Doc. That one machine was the foothold NotPetya needed.

Why nothing could stop it

NotPetya was, in the words of Cisco Talos researcher Craig Williams, the fastest-propagating malware his team had ever seen: "By the second you saw it, your data center was already gone." Its speed came from stitching together two powerful tools. The first was EternalBlue, an exploit developed by the U.S. National Security Agency and leaked earlier in 2017 by a group called the Shadow Brokers. It targets a flaw in a Windows file-sharing protocol (tracked as CVE-2017-0144) and lets an attacker run their own code on any unpatched machine, remotely, with no password needed. The second was Mimikatz, a tool written in 2011 by French researcher Benjamin Delpy to prove a point: that Windows left users' passwords lingering in a computer's memory. Once NotPetya landed on one machine, Mimikatz-style code scraped credentials out of memory and used them to log into other machines on the network, including patched ones. That combination is what made it unstoppable inside a corporate network. As Delpy himself put it, you infect the computers that aren't patched, grab the passwords from them, and then use those passwords to walk into the computers that are patched. Microsoft had released a patch for EternalBlue months earlier, in March 2017. It did not matter. NotPetya also spread using legitimate Windows administration tools, PsExec and WMI, so it looked, at each hop, like an ordinary system administrator doing their job. The security firm ISSP clocked it taking down a large Ukrainian bank's network in 45 seconds and infecting part of a transit hub in 16.

Source: Wikimedia Commons (public domain)
Source: Wikimedia Commons (public domain)

Here is the most persistent misconception about the attack, and it is worth correcting plainly. NotPetya looked exactly like ransomware. It flashed a red-and-black screen demanding $300 in bitcoin to decrypt your files, and it took its name from an earlier piece of genuine criminal ransomware called Petya. But paying was pointless. On 28 June 2017, Kaspersky's Securelist team showed why: the "installation ID" the malware displayed for victims to send to the attackers was just random data, generated by a function called CryptGenRandom. Real ransomware embeds the information needed to recover a decryption key inside that ID. NotPetya's contained nothing. No key ever existed. It had irreversibly scrambled the master boot record, the deep part of a disk that tells a computer where to find its own operating system, and there was no way back. It was a wiper wearing a ransomware mask. Destruction was the point; the ransom was theatre.

The part of the network no one thought to back up

Maersk's technicians, working from an emergency operations centre, eventually located backups for almost all of the company's individual servers, dating from three to seven days before the attack. Then they hit a wall that turned the crisis existential. To understand it, you need one piece of jargon: the domain controller. In a large Windows network, domain controllers are the servers that hold the master map of the whole system. They store the list of users, the passwords, and the rules about who is allowed to access what. Without a working domain controller, the thousands of other servers and machines have no way to authenticate anyone or trust each other. As one Maersk staffer put it, "if we can't recover our domain controllers, we can't recover anything." Maersk had roughly 150 domain controllers spread around the world. The design was, on paper, resilient: they were all programmed to synchronise their data with one another, so that if any one failed, the others could serve as its backup. What the design never contemplated was every single one of them being wiped at the same instant. That is precisely what NotPetya did. The distributed backup strategy had a hidden single point of failure baked into its own logic, and no one had made a separate, offline backup of the domain controllers, because the system was supposed to be its own backup. So the servers that held the keys to the entire kingdom were gone, all 150 of them, simultaneously. Without them, the several days of server backups Maersk had painstakingly recovered were close to useless.

One machine in Ghana, saved by a blackout

What saved Maersk was an accident of the electrical grid in West Africa. After a frantic search that involved calling hundreds of IT administrators in data centres around the world, the recovery team found a single surviving domain controller in a remote office in Ghana. Shortly before NotPetya struck, a local blackout had knocked that machine offline and it had stayed disconnected from Maersk's network. Because it was dark and unplugged when the worm swept through, the malware never reached it. That one accidental power cut meant the machine held the only untouched copy of Maersk's domain controller data left on Earth. "There were a lot of joyous whoops in the office when we found it," one administrator recalled. Recovering the data from it was its own ordeal, and it reads like a heist. When engineers in England tried to pull the several-hundred-gigabyte backup across the wire, the Ghanaian office's internet connection was far too thin to move it in any reasonable time. The next plan was to fly a Ghanaian staffer with the drive to London, but none of the West African office's employees held a British visa. So Maersk arranged a relay race: one staffer from the Ghana office flew to Nigeria and handed the drive to another Maersk employee in the airport, who then boarded a six-and-a-half-hour flight to Heathrow, carrying what Wired called the keystone of Maersk's entire recovery in hand luggage.

Source: Zandcee, via Wikimedia Commons (CC BY-SA 3.0)
Source: Zandcee, via Wikimedia Commons (CC BY-SA 3.0)

While that drive was in transit, the real-world consequences were piling up in ports on every continent. Maersk's ships themselves were not infected, but the terminal software that reads the electronic manifests telling operators what is inside each of the 18,000 containers on an arriving vessel had been wiped. At the terminal in Elizabeth, New Jersey, where about 3,000 trucks arrive on a normal day, the automated gates simply went silent. Within hours, hundreds of eighteen-wheelers were backed up in a line stretching for miles, many of them carrying refrigerated "reefer" containers full of perishable goods that would rot if they could not be plugged in. The same scene played out at 17 of Maersk's 76 terminals worldwide, from Los Angeles to Rotterdam to Mumbai. For a while, one customer recounted, the only way to book cargo was by hand: staff taped paper documents to containers and took orders over personal Gmail accounts, WhatsApp, and Excel spreadsheets. "It's a fairly bizarre experience to find yourself booking 500 shipping containers via WhatsApp," the customer said, "but that's what we did."

Ten days, two months, and the bill

At an emergency recovery centre in Maidenhead, west of London, Maersk had converted two floors of an office building into a 24/7 operation. The consultancy Deloitte was handed what amounted to a blank cheque, and at peak up to 200 Deloitte staff worked alongside as many as 400 Maersk personnel. Every piece of pre-attack equipment was confiscated for fear of reinfection, so staff bought up piles of new laptops and prepaid Wi-Fi hotspots from local electronics shops and were told to find a corner and get to work. Back in Copenhagen, the basement cafeteria became a reinstallation assembly line, 20 machines at a time laid out on dining tables while help-desk staff walked the rows plugging in USB drives. Five months later, at the World Economic Forum in Davos in January 2018, Maersk chairman Jim Hagemann Snabe described the effort onstage. In ten days, he said, the company rebuilt its entire network: 4,000 new servers, 45,000 new PCs, and 2,500 applications. Work that would normally take six months was compressed into a week and a half. "We overcame the problem with human resilience," he told the crowd. What he did not dwell on is that full recovery took far longer; some staff at Maidenhead worked day and night for close to two months to fully restore Maersk's software, and every employee lost whatever they had stored locally on their own machines, from work notes to family photos. Snabe estimated the attack cost Maersk between $250 million and $300 million, though Wired reported that many of the staff involved privately suspected the accountants had low-balled it. Snabe also claimed the company suffered only a 20 percent drop in shipping volume during the outage, thanks to the manual workarounds. And Maersk got off relatively lightly. Across the wider world, NotPetya inflicted nine-figure losses on company after company: $870 million at the pharmaceutical giant Merck, about $400 million at FedEx's European subsidiary TNT Express, roughly the same at the French construction firm Saint-Gobain, $188 million at the snack maker Mondelez, and $129 million at Reckitt Benckiser. The White House later put the total damage at more than $10 billion, making NotPetya, by that measure, the most destructive cyberattack in history.

What Maersk knew, and what came after

The uncomfortable coda is that Maersk had been warned. Security staff told Wired that some of the company's servers were still running Windows 2000, an operating system so old that Microsoft no longer supported it. In 2016, a group of IT executives had pushed for a preemptive security overhaul of the entire global network, flagging weak patching, outdated systems, and above all insufficient network segmentation, the practice of dividing a network into isolated compartments so that malware loose in one part cannot rampage through the whole. That is exactly the weakness NotPetya would exploit a year later. The overhaul was approved and budgeted. But because its completion was never tied to any senior manager's performance targets or bonus, it quietly stalled and was never carried out.

Source: Julian Herzog, via Wikimedia Commons (CC BY 4.0)
Source: Julian Herzog, via Wikimedia Commons (CC BY 4.0)

The politics moved slowly too. On 15 February 2018, the UK government formally attributed the attack. "The Russian Government, specifically the Russian military, was responsible for the destructive NotPetya cyber-attack of June 2017," said Foreign Office minister Lord Ahmad, condemning its "reckless" release. The United States, Australia, New Zealand, Canada, and Denmark said the same. Former Homeland Security adviser Tom Bossert, then President Trump's most senior cybersecurity official, confirmed the $10 billion figure to Wired and called the attack "the equivalent of using a nuclear bomb to achieve a small tactical victory." Russia denied everything, dismissing the accusations as "Russophobic." U.S. sanctions did not arrive until roughly eight months after the attack, bundled together with punishments for unrelated matters. Thomas Rid, a professor at Johns Hopkins, warned that such a muted response was "almost an invitation to escalate." The deeper lesson of NotPetya is not really about Maersk, or even about backups, though "keep an offline copy of your domain controllers" is a lesson many organisations learned the hard way that summer. It is about the strange geometry of this kind of warfare. A weapon released in a server room in Kyiv, aimed at Ukrainian tax software, ended up freezing port gates in New Jersey and Los Angeles, halting a chocolate factory in Tasmania, and knocking out a Danish shipping empire, all within hours, all without a single soldier crossing a border. There is a widespread assumption that the international damage was accidental spillover. Not everyone believes that. Cisco's Craig Williams argued that Russia knew full well how far NotPetya would spread, and that the message was deliberate: if you do business in Ukraine, bad things will happen to you. Either way, the thing worth watching is not whether it happens again but how much worse the next one is. Maersk survived because a machine in Ghana happened to be unplugged. That is not a security strategy. It is luck. The question every large, interconnected organisation inherited from June 2017 is uncomfortable and still largely unanswered: in a domain where distance offers no protection and a neighbour's bad day becomes your catastrophe at the speed of a network sync, what exactly counts as being prepared?

Sources

  1. Wired, "The Untold Story of NotPetya, the Most Devastating Cyberattack in History" (Andy Greenberg), 2018.
  2. Kaspersky Securelist, "ExPetr/Petya/NotPetya is a Wiper, Not Ransomware", 2017.
  3. ESET WeLiveSecurity, "TeleBots are back: Supply-chain attacks against Ukraine", 2017.
  4. UK Government / Foreign & Commonwealth Office, "Foreign Office Minister condemns Russia for NotPetya attacks", 2018.
  5. The Register, "IT 'heroes' saved Maersk from NotPetya with ten-day reinstallation blitz", 2018.
  6. Dark Reading, "White House: Russian Military Behind NotPetya Attacks", 2018.
  7. Global Trade Magazine, "White House Acknowledges Russia Behind 2017 NotPetya Cyber Attack", 2018.
  8. Wikipedia, "Petya (malware family)", accessed 2026.
  9. Wikipedia, "2017 Ukraine ransomware attacks", accessed 2026.