Cutting Sword of Justice is the name used by the actors who claimed responsibility for the 2012 destructive cyberattack against Saudi Aramco. The operation is widely associated with the Shamoon, also known as Disttrack, wiper malware and is notable for large-scale sabotage of corporate IT systems rather than conventional hacktivist-style denial-of-service activity. Public claims framed the attack as retaliation for Saudi policies in the Middle East, but multiple accounts cited in reporting and later analysis assessed the activist branding may have been a cover narrative and linked the operation to Iran or a suspected Iranian threat actor. The group is chiefly known for targeting Saudi Aramco in Saudi Arabia’s energy sector. The attack reportedly destroyed data on roughly 30,000 workstations and replaced files with political imagery, while the victim stated production operations were not affected because business systems were segregated from operational networks. Subsequent reporting on Shamoon 2.0 in 2016 described the earlier 2012 Shamoon activity as attributable to a suspected Iranian group using the Cutting Sword of Justice name. Activity associated with this actor demonstrates destructive post-compromise tradecraft and lateral propagation inside Windows enterprise environments. Reported behaviors include use of malware with disk-wiping functionality, abuse of privileged access, credential harvesting or use of embedded privileged credentials, scanning of local subnets, propagation via administrative shares, enabling Remote Registry, modifying system settings to facilitate remote execution, and scheduling tasks to launch the destructive phase. The actor’s known operations are best characterized as politically motivated sabotage aligned with Iranian geopolitical interests rather than financially motivated cybercrime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Suspected Iranian-linked destructive operations using the Shamoon (Disttrack) wiper, including the 2012 incident and discussion of later Shamoon 2.0 activity in the Gulf region.
Claimed responsibility for the Shamoon attack against Saudi Aramco and framed the operation as politically motivated hacktivism, using public messaging to recruit like-minded anti-tyranny hacker groups.
Claimed responsibility for the destructive sabotage attack against Saudi Aramco that erased data on a large portion of corporate PCs.
Claimed responsibility for a destructive malware attack against Saudi Aramco, saying they infected company workstations, destroyed large numbers of computers, and threatened a follow-on attack.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.