
In the US Central Intelligence Directorate, they came to the conclusion that the Petya-Monk virus (also called notpetya) was created with the participation of the Main Directorate of the General Staff of the Russian Armed Forces (former GRU). It is reported by The Washington Post with reference to sources.
The fact that Russian military intelligence is involved in the creation of Petya with a high degree of probability, the CIA’s secret report issued in November said, sources said. It is noted that the attack began on June 27, on the Day of the Constitution of Ukraine. The attack was conducted with the aim of paralyzing the country's financial system.
The CIA was refused from official comments.
On June 27, computer networks of the Government of Ukraine, the Kiev Gorgosa Administration, dozens of state and private large banks and companies becamevictims of a massive cyber attack , which in some cases led to the stop of their operations. The reason was the Petya-Monk virus that blocks the loading of the operating system. A message demanding a ransom ($ 300 in bitcoins) said that the virus uses the "military encryption algorithm" and encodes the entire hard drive at once.
The attack began with Ukraine, which was most affected by cyber attacks, but the virus quickly spread around the world. According to the ESET antivirus laboratory, in the top ten countries that the virus affected the most sensitive, Italy, Israel, Serbia, Hungary, Romania, Poland, Argentina, the Czech Republic and Germany also entered.
In Russia, which was in 14th place, the Rosneft and Bashneft server, the Evraz metallurgical company and a number of smaller companies were subjected to the virus attack.
On July 1, the Security Service of Ukraine accused the Russian special services of involvement in the spread of the Petya virus. According to the SBU, the goal of cyber attack was not enrichment, but the "destabilization of the socio-political situation" in Ukraine. The virus allegedly had to destroy important data, as well as violate the work of state and private institutions of the country "to spread panic moods" among the population. The special services also noted that the infection was planned and carried out in advance.
According to the SBU, the same hacker groups were involved in the attacks that in December 2016 they attacked the financial system, objects of transport and energy of Ukraine. "This indicates the involvement of the special services of the Russian Federation in this attack," the SBU claimed.