The M.E.Doc Backdoor Behind NotPetya
Updated 5 Oct 2026 · Incident date 22 Jun 2017 · vendor binary
M.E.Doc 10.01.188 -> 10.01.189 (earlier backdoored updates 10.01.176 on 14 Apr 2017 and 10.01.181 on 15 May 2017)ZvitPublishedObjects.dllThree updates of the Ukrainian accounting software M.E.Doc carried a backdoor in ZvitPublishedObjects.dll. They are 10.01.175 to 10.01.176 on 14 April 2017, 10.01.180 to 10.01.181 on 15 May 2017, and 10.01.188 to 10.01.189 on 22 June 2017.
The attackers used the backdoor to deliver the XData and NotPetya ransomware.
Major incident. Microsoft observed infections in Ukraine and another 64 countries after the NotPetya outbreak. Impact source
What happened
The update servers of the vendor, Intellect Service, delivered the backdoored DLL as a normal update. BleepingComputer reports that a Ukrainian official said the vendor had installed no updates on the affected servers since February 2013. Ukrainian police seized the vendor's servers on 4 July 2017 and stopped a second attack wave that had started.
ESET analyzed the DLL. It is a 5 MB .NET file, and the backdoor class is named MeCom. The backdoor collected:
- EDRPOU numbers, the Ukrainian legal entity identifiers
- proxy settings and credentials
- email account user names and passwords
It saved them in the registry under HKEY_CURRENT_USER\SOFTWARE\WC, in values named Cred and Prx. It talked to the vendor's update host, upd.me-doc.com.ua, and hid its data in HTTP cookies, so no separate command server was needed. It had six commands, including shell execution, file extraction, system reconnaissance and running a DLL through rundll32.exe.
Affected versions
ESET and BleepingComputer name three backdoored update ranges.
- 10.01.175 to 10.01.176, released 14 April 2017
- 10.01.180 to 10.01.181, released 15 May 2017
- 10.01.188 to 10.01.189, released 22 June 2017
The 22 June update came days before the NotPetya outbreak on 27 June. Updates before April 2017 were clean.
Indicators of compromise
- ESET detection name:
MSIL/TeleDoor.A ZvitPublishedObjects.dllSHA-1:7B051E7E7A82F07873FA360958ACC6492E4385DDZvitPublishedObjects.dllSHA-1:7F3B1C56C180369AE7891483675BEC61F3182F27ZvitPublishedObjects.dllSHA-1:3567434E2E49358E8210674641A20B147E0BD23C- Registry key
HKEY_CURRENT_USER\SOFTWARE\WCwith valuesCredandPrx - Traffic to
upd.me-doc.com.uawith data in cookies
How to check
Hash the DLL in the M.E.Doc folder and compare it with the SHA-1 values above.
Get-ChildItem -Path C:\ -Recurse -Filter ZvitPublishedObjects.dll -ErrorAction SilentlyContinue | Get-FileHash -Algorithm SHA1
Then check for the registry key that the backdoor used.
reg query HKCU\SOFTWARE\WC
What to do now
- Isolate any machine with a matching hash or the registry key.
- Change the email and proxy credentials the backdoor could read.
- Check the machine for the ransomware and for other tools that were delivered.
- Restore from a backup made before the first bad update, 14 April 2017, where you need a clean state.
- Take any software update channel into account in your network design. Limit what the accounting host can reach.
Vigilance compares the version you trust with a new one and reports the file that gained a new capability. Here an existing DLL gained credential reading, command traffic and payload execution. See all attacks.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 81 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED ZvitPublishedObjects.dll It now downloads from the internet and reads saved passwords and access keys. It did not before.
Frequently asked questions
Which M.E.Doc versions were backdoored?
Updates 10.01.175 to 10.01.176 (14 April 2017), 10.01.180 to 10.01.181 (15 May 2017) and 10.01.188 to 10.01.189 (22 June 2017).
How do I check for the M.E.Doc backdoor?
Hash ZvitPublishedObjects.dll and compare it with the SHA-1 values published by ESET. Also check for the registry key HKCU\SOFTWARE\WC.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.