Shamoon 2 resurfaced as a destructive Disttrack malware campaign targeting organizations in Saudi Arabia, reviving tooling and tradecraft associated with the 2012 Shamoon attacks. Researchers said the malware was built to overwrite files, corrupt partition data, and render systems unusable by abusing the signed EldoS RawDisk driver to access and wipe protected disk structures including the MBR and partition tables. Analysis of both the 2012 and 2016-era samples showed the malware masquerading as legitimate Windows components such as trksvr.exe, reusing service-related artifacts and disk-wiping functionality consistent with the original Shamoon family.
The later attack waves relied on stolen administrator credentials, RDP access, a compromised internal distribution server, PAExec, and batch scripts to copy and execute Disttrack across named hosts identified through Active Directory and prior reconnaissance. Palo Alto Networks reported that infected hosts attempted to spread to as many as 256 additional IP addresses on their local subnet, while the malware’s hardcoded wipe timing and non-operational C2 indicated the operation prioritized destruction over persistence. Separate Securelist research also described a related Shamoon-themed wiper using RawDisk and MBR-erasure techniques, but assessed it as a likely copycat rather than the original Iran-targeting wiper, underscoring how Shamoon’s destructive methods continued to influence later malware development.

TTPs, infrastructure, and targeting history in one profile.
11 events from the most recent confirmed update back to the earliest known activity.
Analyzed Disttrack samples from the renewed campaign were configured to begin wiping data at 20:45 on 2016-11-17. Researchers noted the timing aligned with the start of the Saudi weekend.
Beginning in late November 2016, Shamoon 2 conducted three waves of destructive attacks against organizations in Saudi Arabia. The operation relied on stolen credentials, remote access, and internal distribution mechanisms to deploy Disttrack.
In November 2016, Unit 42 identified new Disttrack samples tied to an updated Shamoon campaign targeting at least one organization in Saudi Arabia. The malware reused key elements associated with the 2012 Shamoon attacks.
On 2012-08-16, two Shamoon/DistTrack samples were observed on VirusTotal with detection ratios of 22/42 and 21/42. Multiple vendors identified them as DistTrack-family malware.
Two Shamoon/DistTrack malware samples analyzed later carried PE timestamps of 2012-08-10 00:46:22+02:00, indicating the binaries were built by that date. The samples masqueraded as the Windows Distributed Link Tracking Server executable.
In August 2012, the original Shamoon campaign targeted a Saudi Arabian energy company with Disttrack malware. The attack damaged 30,000 or more systems.
After comparing the sample with the malware used against Iran in April 2012, researchers concluded it was probably not the same original Wiper malware. They cited differences in service names, driver filename patterns, and disk-wiping behavior, and assessed it was more likely a copycat inspired by earlier destructive attacks.
Over a 24-hour telemetry window, researchers observed only two sightings of Trojan.Win32.EraseMBR.a, both apparently involving security researchers in China. They concluded the malware was not widespread and was likely used in narrowly targeted attacks.
Kaspersky researchers said they received a collection of malware samples from another anti-malware company, including one containing the path string "C:\Shamoon\ArabianGulf\wiper\release\wiper.pdb". Analysis showed it abused a signed EldoS driver for raw disk access and MBR wiping.
Unit 42 reported a possible but unconfirmed connection between Shamoon 2 and the Magic Hound campaign based on overlapping Saudi targeting, similar cloud-hosted infrastructure, and use of PowerShell and Meterpreter. The evidence was described as suggestive rather than conclusive.
During the Shamoon 2 operation, attackers first compromised an internal system used as a Disttrack distribution server, accessed it over RDP with stolen credentials, and downloaded a ZIP archive containing deployment tools and hostname lists. The recovered materials showed a semi-automated method for copying and executing Disttrack across named hosts.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 21 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
securelist.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourcecontagiodump.blogspot.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.