Shamoon, also known as Disttrack, is a destructive Windows malware family best known for large-scale wiper attacks against organizations in the energy sector, including the 2012 attack on Saudi Aramco. It is designed to cause operational disruption rather than generate revenue, and is notable for combining destructive disk wiping with limited propagation and pre-wipe collection activity. Shamoon has been widely associated with Iranian threat activity, and public reporting has linked it in various contexts to Iranian state or state-aligned operators; APT33 has frequently been discussed in connection with later Shamoon activity, although attribution has not always been definitive.
Shamoon operates by spreading through accessible network shares and executing remotely on additional Windows systems. It has been observed enabling the RemoteRegistry service on target hosts, modifying registry settings to reduce remote access restrictions, and creating Windows services to launch its payload. It also copies payload components to target systems and can schedule execution through tasks. For destructive impact, Shamoon queries the Windows Registry to identify disk partitions, gains low-level access to storage, overwrites files and disk structures, and rewrites the master boot record so affected machines fail to boot. Some variants also altered file timestamps to hinder forensic reconstruction. Historical reporting also describes Shamoon using a legitimately signed disk-access driver to interact directly with the filesystem.
The malware has been described as conducting a two-stage operation in some campaigns: first scraping or collecting data from other reachable systems over network shares, then wiping local and remote systems. Its self-propagation through shared disks and its emphasis on irreversible destruction distinguish it from conventional espionage implants. Shamoon has also been cited among malware families that used steganographic techniques in some contexts.
Victimology has centered on Middle Eastern energy and industrial organizations, with the most prominent incidents affecting Saudi and Qatari energy companies. Shamoon remains a landmark example of politically motivated destructive malware and a reference point for later wiper operations targeting enterprise Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The wiper rewrites the master boot record (MBR) on connected drives so when the victim next turns on the device, the “From Iran with love – Shamoon” message appears on the screen, and the operating system will not load.
Iranian attack groups mostly operate below the radar of major news coverage (with the exception of the Shamoon attacks).
The virus, named Shamoon after a word in its code, was designed to overwrite critical files with an image of a burning American flag.
"CHRYSENE developed from an espionage campaign that first gained attention after the destructive Shamoon cyberattack in 2012 that impacted Saudi Aramco."
The wiper, identical to the Shamoon malware, rewrites the master boot record (MBR) on connected drives and overwrites all file contents with randomly generated bytes, effectively preventing system recovery.
Researchers have identified a possible new collaborator in the continued Shamoon attacks against Saudi organizations... helping Shamoon steal user credentials of targets ahead of Shamoon’s destructive attacks.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.
Avaddon modifies several registry keys for persistence and UAC bypass ... Lokibot has modified the Registry as part of its UAC bypass process ... Shamoon ... modify the Registry to disable UAC remote restrictions by setting ... LocalAccountTokenFilterPolicy to 1.
It also uses what appears to be a legitimate system driver to gain low-level access to a hard drive... The driver, according to Kaspersky, was digitally signed using the private cryptographic key belonging to a company called EldoS Corporation.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
Aquatic Panda created new Windows services for persistence that masqueraded as legitimate Windows services via name change.
Deletes an existing driver from the following location and overwrites it with another legitimate driver: %System%\drivers\drdisk.sys
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
Our analysis shows a signed driver is being used to deploy a wiper that targets Windows devices... The developers are using a tried and tested technique of wiper malware, abusing a benign partition management driver... HermeticWiper uses a similar technique by abusing a different driver, empntdrv.sys.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Once a system on a network is infected, the code scrapes data from other systems via network shares, including those not connected to the internet.
Examples include "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "DropBook has checked for the presence of Arabic language," and "Maze has checked the language of the infected system using the GetUSerDefaultUILanguage function."
Shamoon copies an executable payload to the target system by using SMB/Windows Admin Shares and then scheduling an unnamed task to execute the malware.
The malware also reports back to the attackers with information about the number of files that were destroyed, the IP address of the infected computer, and a random number.
IT Windows based Saudi Aramco PCs >35K begin shutting down & being wiped • 15 August 2012
Unlike many other contemporary viruses Shamoon/Disstrack does not attempt to steal data but instead tries to delete it irrecoverably.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
92 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive malware/wiper referenced as a historical case in discussion of cyber conflict history.
Referenced as historical comparison for destructive malware focused on immediate operational impact.
A destructive wiper virus known for crippling Saudi Aramco in 2012, cited as evidence of Iran’s longstanding offensive cyber capability.
Семейство вредоносного ПО, упомянутое как использующее стеганографию для сокрытия данных или коммуникаций.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.