Shamoon is the operator cluster associated with the Shamoon destructive malware campaigns, including the Disttrack wiper, and is widely assessed as an Iran-linked threat actor. The group is best known for large-scale disk-wiping attacks against organizations in Saudi Arabia, with major activity including the Shamoon 2 campaign that launched multiple waves of destructive intrusions beginning in late 2016. Reporting has also noted possible but unconfirmed relationships or overlap with other Iran-linked activity clusters such as Greenbug and Elfin/APT33. Shamoon operations emphasize destructive impact rather than conventional espionage or financially motivated crime. In documented Shamoon 2 intrusions, the operators relied on sustained pre-attack access, stolen legitimate credentials, and remote administration methods to prepare victim environments before detonating the wiper. They used Remote Desktop Protocol access to a compromised internal distribution server, batch scripts, and remote execution utilities including PAExec, with indications they may also have used PsExec-style tradecraft. Host targeting appears to have been informed by Active Directory data or prior internal reconnaissance, enabling semi-automated propagation across known systems in the victim network. Once deployed, Disttrack was copied to remote hosts, executed via scripts and scheduled-task style mechanisms, and then attempted further spread across local subnets while preparing systems for wiping at a predefined time. The operators also attempted to clear Windows event logs to hinder incident response and forensic reconstruction. This combination of credential theft, lateral movement, remote execution, propagation, and defense evasion made Shamoon particularly effective at scaling destructive effects inside enterprise environments. Shamoon has also been cited among malware families observed using steganographic techniques, though the actor’s defining characteristic remains destructive disk wiping against regional targets, especially in Saudi Arabia. Known aliases include Shamoon Group, Shamoon (operators cluster), and Shamoon (wiper operators).
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive group mentioned only as possibly linked to Elfin activity.
Named malware/activity cluster explicitly listed as using steganography in attacks.
Referenced as a possibly connected destructive group associated with disk-wiping attacks; cooperation with Greenbug is discussed as a possibility but not definitively established.
Referenced as a distinct group associated with a wave of attacks in Saudi Arabia; the content notes speculation about links to Elfin but says no further evidence supports Elfin being responsible.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.