Shamoon, also tracked as Disttrack and W32.Disttrack, was used in destructive attacks against energy-sector organizations including Saudi Aramco and later RasGas, knocking large numbers of Windows systems offline while leaving oil and gas production operations largely unaffected. Saudi Aramco said about 30,000 computers were impacted, and RasGas took desktops, email, and web servers offline after detecting similar malicious activity. Security reporting tied the incidents to a targeted campaign against Middle Eastern energy firms rather than conventional cybercrime, with the malware designed to cause disruption instead of maintain stealthy access.
Researchers described Shamoon as a three-part framework consisting of a dropper, wiper, and reporter module. After spreading through administrative shares in Windows environments, it collected selected data, reported infection statistics to operators, and then used a legitimately signed disk driver to overwrite files and corrupt the Master Boot Record (MBR), rendering machines unusable; some analyses also noted a built-in kill timer and development artifacts linked to the name “Shamoon.” Later reporting said the malware resurfaced after its initial 2012 attacks, reinforcing its reputation as an effective if relatively unsophisticated wiper built for high-impact sabotage against enterprise IT networks.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
On November 30, 2016, Symantec reported that Shamoon had resurfaced and was again being used in destructive attacks. The publication marked the malware family's re-emergence years after the 2012 energy-sector incidents.
In September 2012, further analysis characterized Shamoon's code as relatively unsophisticated while still highly effective at causing destructive impact. The reporting reinforced assessments that the malware was purpose-built for wiping systems rather than stealthy long-term espionage.
Qatar-based RasGas shut down desktop computers, email, and web servers after detecting an unknown virus in late August 2012. The company said production was not affected, and reporting linked the incident to concerns about Shamoon targeting energy firms.
By late August 2012, Saudi Aramco disclosed that the malware incident had disrupted about 30,000 computers. The company reiterated that business systems were affected but oil production systems were not.
Analysis published in late August 2012 reported that Shamoon contained a kill timer, suggesting a preconfigured execution schedule and a possible connection to the Saudi Aramco incident. This added new technical insight into how the malware was designed to trigger its destructive phase.
On 2012-08-23, a group calling itself the 'Cutting Sword of Justice' claimed responsibility for the August 15 malware attack on Saudi Aramco, describing it as retaliation for Saudi government actions. The group said about 30,000 computers were destroyed, posted alleged infected IP addresses as proof, and threatened a second attack for the following Saturday.
Symantec disclosed technical details on August 16, 2012, describing W32.Disttrack as destructive malware used in targeted attacks against at least one energy-sector organization. It outlined the malware's Dropper, Wiper, and Reporter components and its ability to spread via administrative shares, overwrite files, and corrupt the master boot record.
Saudi Aramco was struck by the Shamoon (Disttrack) malware in mid-August 2012 after it reportedly entered through personal computers on the network. The attack disrupted corporate systems while the company said oil production and operational plant systems were not affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
15 references tracked. Mallory keeps watching after this page renders.
security.com
Open sourcedarkreading.com
Open sourcebbc.co.uk
Open sourcecnet.com
Open sourcearstechnica.com
Open sourcearstechnica.com
Open sourcecommunity.broadcom.com
Open sourceblackhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.