Dubbed Fakesomware by Comae (Also called ExPetr, PetrWrap, NotPetya, DiskCoder). TL;DR: The ransomware was a lure for the media, this variant of Petya is a disguised wiper. Update1: Few hours later, Kaspersky’s research led to a similar conclusion. Update2: Added more info on the wiper command & comparative screenshots of the two keys that visually confirms Kaspersky’s finding and why the MBR copy