Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Shamoon

Shamoon

TLP:CLEAR
Family

Also known as: Disttrack

AI Analysis

· 5 hours ago

Executive Summary

Shamoon is a destructive wiper capable of overwriting critical system components and erasing logs, thereby causing irreversible damage across corporate networks. First used in 2012 by an Iranian group, its variants (1–3) have targeted high‑value sectors such as oil & gas. Detection hinges on identifying raw disk writes, anomalous PowerShell activity, and the presence of known Shamoon binaries.

Enhanced Description

Shamoon is a destructive wiper malware first deployed by the Iranian hacking group known as the Cutting Sword of Justice in 2012. The weapon gained notoriety for its large‑scale attacks against critical infrastructure, most famously the 2012 incident that crippled Saudi Aramco’s network by overwriting the master boot record, wiping key system files, and erasing logs to evade detection. Subsequent variants—Shamoon 2 (2016) and Shamoon 3 (2018)—expanded on this behavior with more sophisticated persistence techniques, larger payloads, and improved concealment mechanisms. All known iterations employ the RawDisk API and third‑party utilities such as Filerase to perform low‑level disk writes that bypass traditional file‑system monitoring. The malware also creates a uniquely named malicious executable (often a .dll or .exe resembling “SHAM…”) and may use PowerShell scripts to download auxiliary components from command–control servers via SMB shares. Throughout its deployment it deletes event logs, disables Windows services, and modifies registry keys to prevent rollback, ensuring that the system remains in a destroyed state even after reboots. Beyond data destruction, Shamoon has been linked to Kwampir through shared code snippets and cryptographic signatures. This relationship points to a broader ecosystem of Iranian state‑sponsored malware families that share development tools and infrastructure, increasing both their potency and the likelihood of overlapping indicators across attacks.

Key Capabilities

  • Disk wiping using RawDisk API
  • Low‑level overwrite of master boot record
  • Event log deletion
  • Registry manipulation to disable recovery
  • Use of Filerase for persistent data destruction
  • Command & control via SMB shares and PowerShell scripts

ATT&CK Techniques

T1486
T1105
T1059
T1047

Recommended Actions

  • Deploy endpoint detection that monitors raw disk write attempts (e.g., Sysmon rule E006)
  • Block outbound traffic to known Shamoon C2 IPs such as 173.249.86.71
  • Configure antivirus to detect the signature string ‘SHAM’ in executable names
  • Implement strict SMBv1 protection and disable legacy services
  • Apply regular OS patches and enforce least privilege on all accounts
  • Enable file integrity monitoring for system directories (C:\Windows\\System32)

Suggested Tags

wiper
Iranian threat actor
Shamoon 1
Shamoon 2
Shamoon 3
Cutting Sword of Justice
RawDisk API
Filerase
Kwampir
Data destruction

Confidence Assessment

Given the publicly documented incidents, documented code similarities with established Iranian threat actors, and repeated use of RawDisk/Filerase APIs, confidence in identifying Shamoon’s destructive capabilities is high. However, detailed persistence methods for newer variants and full command‑and‑control infrastructure remain partially characterized, limiting a complete behavioral profile.

Description

Shamoon is wiper malware that was first used by an Iranian group known as the "Cutting Sword of Justice" in 2012. Other versions known as Shamoon 2 and Shamoon 3 were observed in 2016 and 2018. Shamoon has also been seen leveraging RawDisk and Filerase to carry out data wiping tasks. Analysis has linked Shamoon with Kwampirs based on multiple shared artifacts and coding patterns.(Citation: Cylera Kwampirs 2022) The term Shamoon is sometimes used to refer to the group using the malware as well as the malware itself.(Citation: Palo Alto Shamoon Nov 2016)(Citation: Unit 42 Shamoon3 2018)(Citation: Symantec Shamoon 2012)(Citation: FireEye Shamoon Nov 2016)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.