In the case of Wannacry, attribution is very difficult and finding links with previously known malware is challenging. Nobody has been able to find any significant code sharing between ExPetr/Petya and older malware. The BlackEnergy APT is a sophisticated threat actor that is known to have used at least one zero day, coupled with destructive tools, and code geared towards attacking ICS systems. The list of extensions used by Expetr is very similar to the one used by BlackEnergys KillDisk ransomware from 2015 and 2016.”]
Source: https://securelist.com/from-blackenergy-to-expetr/78937/

