Palo Alto Networks Unit 42 reported a second wave of Shamoon 2 attacks, a destructive malware campaign that targeted organizations in the Middle East and used disk-wiping functionality to disrupt operations. The activity followed the re-emergence of the Shamoon malware family and reflected a renewed effort to damage systems rather than steal data, with infected machines rendered unusable after the malware overwrote critical files and the master boot record.
The report identified the campaign as part of the broader Shamoon 2 resurgence, indicating that attackers continued to refine and redeploy the wiper against regional targets after the initial incidents. For defenders, the attacks underscored the risk posed by destructive malware in enterprise environments, particularly where lateral movement and insufficient segmentation can allow a wiper to spread quickly and cause widespread operational outages.

See attribution, scope, and your downstream exposure.
1 event from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 reported identifying a second wave of Shamoon 2 attacks. No additional event details are provided in the reference beyond the identification of this new wave.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.