Also known as: Cutting Sword of Justice
Shamoon Group is an Iran-linked threat actor associated with destructive Shamoon wiper operations targeting organizations in the Middle East, especially in the energy sector.
Executive Summary
Shamoon Group, also known as Cutting Sword of Justice, is a destructive cyber threat actor linked to Iran, primarily targeting Middle Eastern energy sectors with wiper malware operations.
Goals & Targeting
Shamoon Group targets Middle Eastern energy organizations to disrupt critical infrastructure, likely driven by geopolitical motivations. Their attacks are aligned with strategic interests in the region, focusing on sectors key to national security and economic stability.
Enhanced Description
Shamoon Group is an advanced persistent threat (APT) group attributed to Iran. They are notorious for their use of Shamoon wiper malware, which has caused significant disruption in the Middle East, particularly within the energy sector. Their targeting strategy suggests a focus on critical infrastructure, aligning with broader geopolitical objectives, possibly linked to operations by groups like APT34.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Known for long-term campaigns against energy targets, Shamoon Group has demonstrated persistence and adaptability. Their operations may align with geopolitical events.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate; specific TTPs are inferred, but exact details like techniques used are uncertain.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics