Shamoon, also known as DistTrack, is a destructive Windows malware family best known for large-scale wiper attacks against organizations in the Middle East, particularly the energy sector. First publicly documented in 2012 and later seen in updated waves in 2016 and 2017, it has been widely associated with Iranian state-linked operations and is regarded as one of the most consequential politically motivated wipers used against regional adversaries.
Shamoon combines destructive functionality with pre-wipe collection and propagation features. It can gather host and network information, including local IP and network segment details, obtain system time, and delay activation until a preset date. Some variants include a communications or reporting component capable of uploading victim information and receiving additional payloads, while the core destructive component overwrites files, damages partition data, and corrupts the master boot record to render systems inoperable. The malware has also been described as uploading files to attacker-controlled infrastructure before wiping infected computers.
A notable characteristic of later Shamoon variants is lateral movement within Windows environments. The malware can enumerate nearby systems on the local network, use embedded or stolen administrative credentials, authenticate to remote hosts, enable RemoteRegistry, modify the registry to relax remote UAC restrictions, copy payloads to remote systems, and execute them through remote service creation or scheduled tasks. It also uses obfuscation reversal techniques, including XOR decryption with a Base64-decoded key, to unpack embedded components.
Shamoon is modular, with dropper, communications, and wiper components documented in later campaigns. Its wiper has abused a legitimate raw-disk driver to gain low-level disk access for overwriting protected structures such as the MBR and partition tables. Campaign timing and targeting indicate an emphasis on maximizing operational disruption rather than maintaining long-term covert access. The malware has been linked to attacks that damaged tens of thousands of systems, including the well-known Saudi Aramco incident, and remains a landmark example of state-linked destructive malware used for sabotage and coercive signaling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Shamoon, also known as DistTrack, functions as an information-stealing malware that also incorporates a destructive component that allows it to overwrite the Master Boot Record (MBR) with arbitrary data so as to render the infected machine inoperable.
Shamoon, also known as DistTrack, functions as an information-stealing malware that also incorporates a destructive component that allows it to overwrite the Master Boot Record (MBR) with arbitrary data so as to render the infected machine inoperable.
Comparative forensic analysis has revealed the Kwampirs RAT as having numerous similarities with the data destruction malware Disttrack (commonly known as Shamoon).
Shamoon, also known as DistTrack, functions as an information-stealing malware that also incorporates a destructive component that allows it to overwrite the Master Boot Record (MBR) with arbitrary data so as to render the infected machine inoperable.
The wiper rewrites the master boot record (MBR) on connected drives so when the victim next turns on the device, the “From Iran with love – Shamoon” message appears on the screen, and the operating system will not load.
The virus, named Shamoon after a word in its code, was designed to overwrite critical files with an image of a burning American flag.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The Disttrack malware spreads to other systems automatically using stolen credentials.
The FBI has sent a security alert to the US private sector about an ongoing hacking campaign that's targeting supply chain software providers... 'Software supply chain companies are believed to be targeted in order to gain access to the victim's strategic partners and/or customers, including entities supporting Industrial Control Systems (ICS) for global energy generation, transmission, and distribution,'
this method calls the NetScheduleJobAdd function within the Windows netapi32 library to create a scheduled task to run the payload.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
this method calls the NetScheduleJobAdd function within the Windows netapi32 library to create a scheduled task to run the payload.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The Disttrack malware spreads to other systems automatically using stolen credentials.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
OpenSCManagerW ... OpenServiceW ... CreateServiceW ... ChangeServiceConfigW ... StartServiceW ... RegisterServiceCtrlHandlerW ... SetServiceStatus ... sc config TrkSvr binpath= system32\trksrv.exe && ping -n 10 127.0.0.1 >nul && sc start TrkSvr
BitPaymer can suppress UAC prompts by setting the HKCU\Software\Classes\ms-settings\shell\open\command registry key on Windows 10 or HKCU\Software\Classes\mscfile\shell\open\command on Windows 7... LockBit 2.0 can bypass UAC through creating the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ICM\Calibration.
this method calls the NetScheduleJobAdd function within the Windows netapi32 library to create a scheduled task to run the payload.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The Disttrack malware spreads to other systems automatically using stolen credentials.
OpenSCManagerW ... OpenServiceW ... CreateServiceW ... ChangeServiceConfigW ... StartServiceW ... RegisterServiceCtrlHandlerW ... SetServiceStatus ... sc config TrkSvr binpath= system32\trksrv.exe && ping -n 10 127.0.0.1 >nul && sc start TrkSvr
BitPaymer can suppress UAC prompts by setting the HKCU\Software\Classes\ms-settings\shell\open\command registry key on Windows 10 or HKCU\Software\Classes\mscfile\shell\open\command on Windows 7... LockBit 2.0 can bypass UAC through creating the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ICM\Calibration.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
FileDescription : Distributed Link Tracking Server ... OriginalFilename : trksvr ... SYSTEM\CurrentControlSet\Services\TrkSvr Distributed Link Tracking Server ... C:\Windows\system32\svchost.exe -k netsvcs TrkSvr
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
It then uses the system's IP addresses to enumerate the /24 network (x.x.x.0-255) that the system is networked with, and will attempt to spread to each of these remote systems.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
Examples include 'Bazar can also check if the Russian language is installed,' 'DropBook has checked for the presence of Arabic language,' 'Maze has checked the language of the infected system,' and 'SynAck ... checks installed keyboard layouts to estimate if it has been launched from a certain list of countries.'
After writing itself to the remote system, the dropper creates a service named "ntssrv"... to execute the payload.
Several attacks shared similar methods in that they specifically overwrote the master boot record (MBR) of computers hard drives, which then needed to be physically replaced in many cases.
After overwriting these files and the partition tables, the wiper issues the following command to restart the system
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
128 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive malware/wiper referenced as a historical case in discussion of cyber conflict history.
Referenced as historical comparison for destructive malware focused on immediate operational impact.
Destructive malware/wiper referenced only as part of possible links to activity associated with Elfin.
A destructive wiper virus known for crippling Saudi Aramco in 2012, cited as evidence of Iran’s longstanding offensive cyber capability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.