Credit: Totally Not Russia
To prepare their taxes, folks the world over install janky software developed for a captive market of their nation’s tax laws. In Ukraine, accountants who installed M.E.Doc received a backdoor in the gig and a half of their full installation. The backdoor used M.E.Doc’s own servers for command and control, allowing the network operator to target commands to publicly known tax identification numbers! And yes, this is the alleged patient zero for the NotPetya ransomware that appeared in June, just before Ukraine’s Constitution Day.