Palo Alto Networks Unit 42 reported that Shamoon 3 resurfaced as a destructive malware campaign using a modified open-source wiper, continuing the lineage of the Shamoon attacks that targeted organizations in the Middle East. The malware was designed to overwrite files and disrupt operations, indicating an intent to cause large-scale system damage rather than conduct espionage or financially motivated crime.
Researchers said the updated wiper included a verse from the Quran embedded in the malware, a notable artifact in the sample’s construction, while its use of altered open-source code highlighted how destructive tooling can be rebuilt from publicly available components. The findings underscored that Shamoon remained an active threat capable of being adapted for renewed disruptive attacks against enterprise environments.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 published a report on Shamoon 3, describing it as a modified open-source wiper that contained a verse from the Quran. No additional incident dates or discrete prior events are provided in the reference content.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.