Shamoon

MITRE ATT&CK: S0140 View on attack.mitre.org

Aliases: Disttrack, Shamoon

First seen
2012-08-15 00:00:00
Malware type
wiper
Family
Malware family
Operating systems
windows
Last IoC activity
2026-07-20 18:02:16
Profile updated
2026-07-07 12:42:52

Targeted industries: energy-and-utilities government-and-public-sector

Targeted regions: country_code:sa

Context

Shamoon is wiper malware that was first used by an Iranian group known as the "Cutting Sword of Justice" in 2012. Other versions known as Shamoon 2 and Shamoon 3 were observed in 2016 and 2018. Shamoon has also been seen leveraging RawDisk and Filerase to carry out data wiping tasks. Analysis has linked Shamoon with Kwampirs based on multiple shared artifacts and coding patterns. The term Shamoon is sometimes used to refer to the group using the malware as well as the malware itself.

Detection coverage

  • 2 YARA rules
  • 610 Sigma rules

Malware & tools used

  • Disk Structure Wipe (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Query Registry (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Data Destruction (attack-pattern)
  • Windows Service (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Domain Accounts (attack-pattern)
  • Service Execution (attack-pattern)
  • Token Impersonation/Theft (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Modify Registry (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • System Shutdown/Reboot (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Timestomp (attack-pattern)
  • Web Protocols (attack-pattern)
  • System Time Discovery (attack-pattern)

Detection rules

  • CRAIU_Apt_ZZ_Orangeworm_Kwampirs_Shamoon_Code (yara-rule)
  • MALPEDIA_Win_Disttrack_Auto (yara-rule)

Reports & references

  • Broadcom/Symantec — Viewdocument (report)
  • Broadcom/Symantec — Shamoon Destructive Threat Re Emerges New Sting Its Tail (report)
  • web.archive.org — Shamoon Attacks (report)
  • Broadcom/Symantec — Viewdocument (report)
  • web.archive.org — Greenbug Cyberespionage Group Targeting Middle East Possible Links Shamoon (report)
  • afyonluoglu.org — 2017%20Fireeye%20M Trends%20Report (report)
  • resources.cylera.com — Cylera%20Labs%20Kwampirs%20Shamoon%20Technical%20Report (report)
  • Broadcom/Symantec — Attacks Against Critical Infrastructrure (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • fortinet.com — The Increasing Wiper Malware Threat (report)
  • CrowdStrike — The Anatomy Of Wiper Malware Part 1 (report)
  • CrowdStrike — The Anatomy Of Wiper Malware Part 3 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Disttrack (report)
  • Broadcom/Symantec — Greenbug Cyberespionage Group Targeting Middle East Possible Links Shamoon (report)
  • Mandiant — Rpt M Trends 2017 (report)
  • malwareindepth.com — Shamoon 2012 (report)
  • researchcenter.paloaltonetworks.com — Unit42 Shamoon 2 Delivering Disttrack (report)
  • zdnet.com — Fbi Warns About Ongoing Attacks Against Software Supply Chain Companies (report)
  • vinransomware.com — Detailed Threat Analysis Of Shamoon 2 0 Malware (report)
  • researchcenter.paloaltonetworks.com — Unit42 Shamoon 2 Return Disttrack Wiper (report)
  • Palo Alto Unit 42 — Shamoon 3 Targets Oil Gas Organization (report)
  • Kaspersky — Shamoon The Wiper Copycats At Work (report)
  • Palo Alto Unit 42 — Unit42 Second Wave Shamoon 2 Attacks Identified (report)
  • contagiodump.blogspot.com — Shamoon Or Disttracka Samples (report)
  • codeandsec.com — Sophisticated Cyberweapon Shamoon 2 Malware Analysis (report)

External references