Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Shamoon Group

Also known as: Cutting Sword of Justice

Description

Shamoon Group is an Iran-linked threat actor associated with destructive Shamoon wiper operations targeting organizations in the Middle East, especially in the energy sector.

AI Analysis

· 2 weeks ago

Executive Summary

Shamoon Group, also known as Cutting Sword of Justice, is a destructive cyber threat actor linked to Iran, primarily targeting Middle Eastern energy sectors with wiper malware operations.

Goals & Targeting

Shamoon Group targets Middle Eastern energy organizations to disrupt critical infrastructure, likely driven by geopolitical motivations. Their attacks are aligned with strategic interests in the region, focusing on sectors key to national security and economic stability.

Enhanced Description

Shamoon Group is an advanced persistent threat (APT) group attributed to Iran. They are notorious for their use of Shamoon wiper malware, which has caused significant disruption in the Middle East, particularly within the energy sector. Their targeting strategy suggests a focus on critical infrastructure, aligning with broader geopolitical objectives, possibly linked to operations by groups like APT34.

Key Capabilities

  • Development and deployment of wiper malware
  • Custom tools for data destruction
  • Targeted attacks against critical infrastructure

MITRE ATT&CK Tactics

Reconnaissance
Execution

ATT&CK Techniques

T1566.001
T1070

Software / Tooling

ShamCC wiper malware

Campaigns & Victims

Known for long-term campaigns against energy targets, Shamoon Group has demonstrated persistence and adaptability. Their operations may align with geopolitical events.

IOC Patterns

  • Custom wiper malware signatures
  • Network indicators related to command-and-control infrastructure

Recommended Actions

  • Implement robust network monitoring for suspicious traffic
  • Use endpoint detection and response (EDR) solutions
  • Conduct regular patching and system updates
  • Educate employees on phishing awareness

Suggested Tags

APT
cyber espionage
energy sector
中东

Confidence Assessment

Moderate; specific TTPs are inferred, but exact details like techniques used are uncertain.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Wiper / Destructive
APT
cyber espionage
energy sector
中东

Details

Type
Unknown
Country of Origin
I
Confidence
50%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.