ShapeShift is a wiper malware linked in reporting to the Iran-aligned threat group APT33. FireEye reported that APT33 used a dropper called DropShot/DROPSHOT, which can deploy either the ShapeShift wiper or the TURNEDUP backdoor; FireEye directly observed DROPSHOT delivering TURNEDUP and also identified samples in the wild that dropped ShapeShift. Depending on configuration, ShapeShift is capable of wiping disks, erasing volumes, and deleting files. FireEye and Kaspersky noted similarities between ShapeShift and the Iran-linked Shamoon malware, while reporting treated them as distinct. The malware is associated with APT33 activity targeting aerospace, defense, aviation, and petrochemical/energy-related organizations in the United States, Saudi Arabia, and South Korea. Reporting also notes Farsi language artifacts in ShapeShift and DropShot tooling and operational activity aligned with Iran Standard Time business hours.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive wiper payload attributed to APT33; noted as having similarities to Shamoon.
Destructive wiper capable of disk wiping, volume erasure, and file deletion depending on configuration; associated with Farsi-language artifacts and delivered by some DROPSHOT samples.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.