Also known as: Disttrack
Executive Summary
Shamoon is a destructive wiper capable of overwriting critical system components and erasing logs, thereby causing irreversible damage across corporate networks. First used in 2012 by an Iranian group, its variants (1–3) have targeted high‑value sectors such as oil & gas. Detection hinges on identifying raw disk writes, anomalous PowerShell activity, and the presence of known Shamoon binaries.
Enhanced Description
Shamoon is a destructive wiper malware first deployed by the Iranian hacking group known as the Cutting Sword of Justice in 2012. The weapon gained notoriety for its large‑scale attacks against critical infrastructure, most famously the 2012 incident that crippled Saudi Aramco’s network by overwriting the master boot record, wiping key system files, and erasing logs to evade detection. Subsequent variants—Shamoon 2 (2016) and Shamoon 3 (2018)—expanded on this behavior with more sophisticated persistence techniques, larger payloads, and improved concealment mechanisms. All known iterations employ the RawDisk API and third‑party utilities such as Filerase to perform low‑level disk writes that bypass traditional file‑system monitoring. The malware also creates a uniquely named malicious executable (often a .dll or .exe resembling “SHAM…”) and may use PowerShell scripts to download auxiliary components from command–control servers via SMB shares. Throughout its deployment it deletes event logs, disables Windows services, and modifies registry keys to prevent rollback, ensuring that the system remains in a destroyed state even after reboots. Beyond data destruction, Shamoon has been linked to Kwampir through shared code snippets and cryptographic signatures. This relationship points to a broader ecosystem of Iranian state‑sponsored malware families that share development tools and infrastructure, increasing both their potency and the likelihood of overlapping indicators across attacks.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Given the publicly documented incidents, documented code similarities with established Iranian threat actors, and repeated use of RawDisk/Filerase APIs, confidence in identifying Shamoon’s destructive capabilities is high. However, detailed persistence methods for newer variants and full command‑and‑control infrastructure remain partially characterized, limiting a complete behavioral profile.
Shamoon is wiper malware that was first used by an Iranian group known as the "Cutting Sword of Justice" in 2012. Other versions known as Shamoon 2 and Shamoon 3 were observed in 2016 and 2018. Shamoon has also been seen leveraging RawDisk and Filerase to carry out data wiping tasks. Analysis has linked Shamoon with Kwampirs based on multiple shared artifacts and coding patterns.(Citation: Cylera Kwampirs 2022) The term Shamoon is sometimes used to refer to the group using the malware as well as the malware itself.(Citation: Palo Alto Shamoon Nov 2016)(Citation: Unit 42 Shamoon3 2018)(Citation: Symantec Shamoon 2012)(Citation: FireEye Shamoon Nov 2016)