Shamoon

Malware updated 3 days ago (2024-11-20T17:37:23.306Z)
Download STIX
Preview STIX
Shamoon is a type of malware, specifically a wiper, known for its destructive capabilities. This malicious software was notably involved in the attack on Saudi Aramco, where it crashed over 30,000 workstations, demonstrating its potential to disrupt operations significantly. The threat actors BlackJack and Twelve have both been found to use variants of Shamoon in their attacks. A particular variant of Shamoon, written in Go, was identified in the attacks by these groups, marking a shift from the original version written in C# that became available due to a leak. The connection between these groups is further strengthened by the identical directories in which they place the Shamoon wiper or its components during their attacks. Furthermore, an instance was recorded where a victim in Saudi Arabia was attacked by another threat group, Elfin, and infected with the Stonedrill malware, shortly after falling victim to a Shamoon attack. This suggests a possible coordination or at least a shared target list among different cybercriminal groups. The widespread use of Shamoon has had significant implications on perceptions of cybersecurity, particularly in the Middle East. Following high-profile cyberattacks such as the Stuxnet attack and the Shamoon wiper attacks, nations in the region began establishing cybersecurity and data-protection frameworks in 2014. Despite the lack of sophistication in the Shamoon wiper virus, its effectiveness in causing disruption underscores the importance of robust cybersecurity measures. It's worth noting that this malware, along with others like AcidRain, doesn't need to be sophisticated to be effective, indicating a shift in the landscape of cyber threats.
Description last updated: 2024-11-15T16:12:54.512Z
What's your take? (Question 1 of 4)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Wiper
Malware
Windows
Iran
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The Stuxnet Malware is associated with Shamoon. Stuxnet, discovered in 2010, is one of the most infamous malware attacks in history. It was a military-grade cyberweapon co-developed by the United States and Israel, specifically targeting Iran's nuclear enrichment facility at Natanz. The Stuxnet worm infiltrated Windows systems, programming logic Unspecified
3
Source Document References
Information about the Shamoon Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
DARKReading
8 days ago
Securelist
2 months ago
DARKReading
8 months ago
DARKReading
a year ago
DARKReading
a year ago
DARKReading
a year ago
DARKReading
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
MITRE
2 years ago
MITRE
2 years ago
MITRE
2 years ago
MITRE
2 years ago
MITRE
2 years ago
MITRE
2 years ago
MITRE
2 years ago
MITRE
2 years ago
Securelist
2 years ago