Shamoon, also known as DistTrack, is destructive Windows malware designed to wipe data and render infected computers unusable. It has been deployed in campaigns attributed to Iranian threat actors, including attacks in 2012, 2016, and 2017, with prominent targeting of energy-sector organizations in the Middle East. Its 2012 attack against Saudi Aramco caused widespread disruption to corporate computers.
Shamoon abuses the legitimate EldoS RawDisk driver to obtain low-level disk access and overwrite hard drives. It also supports an operational mode that encrypts data instead of overwriting it. Destructive execution can be time-triggered: the malware checks the system clock and activates only after a configured date. It can upload files to attacker-controlled command-and-control infrastructure before wiping infected systems.
Within compromised networks, Shamoon collects the infected host's IP address and local network segment, scans associated class-C subnets, and attempts to copy itself to remote computers. It transfers executable payloads to accessible systems and uses scheduled tasks to execute them. To facilitate remote administrative access, it can enable the RemoteRegistry service and modify Windows Registry settings to disable User Account Control remote restrictions. These behaviors support coordinated deployment and destruction across multiple systems in a victim environment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
One recent daisy-chained attack that leveraged lower severity CVEs was called Shamoon. It leveraged CVE-2017-0213 in a vulnerability chain to escalate privileges.
One recent daisy-chained attack that leveraged lower severity CVEs was called Shamoon. It leveraged CVE-2017-0213 in a vulnerability chain to escalate privileges. ... Shamoon also leveraged CVE-2017-11774.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These include Alma Communicator, BONDUPDATER, certutil, Clayslide, DistTrack, DNSExfiltrator, DNSpionage, Dustman, Fox Pane, GoogleDrive RAT, and Helminth.
Shamoon, also known as DistTrack, functions as an information-stealing malware that also incorporates a destructive component that allows it to overwrite the Master Boot Record (MBR) with arbitrary data so as to render the infected machine inoperable.
Shamoon, also known as DistTrack, functions as an information-stealing malware that also incorporates a destructive component that allows it to overwrite the Master Boot Record (MBR) with arbitrary data so as to render the infected machine inoperable.
Comparative forensic analysis has revealed the Kwampirs RAT as having numerous similarities with the data destruction malware Disttrack (commonly known as Shamoon).
Shamoon, also known as DistTrack, functions as an information-stealing malware that also incorporates a destructive component that allows it to overwrite the Master Boot Record (MBR) with arbitrary data so as to render the infected machine inoperable.
The wiper rewrites the master boot record (MBR) on connected drives so when the victim next turns on the device, the “From Iran with love – Shamoon” message appears on the screen, and the operating system will not load.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
136 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive malware/wiper referenced as a historical case in discussion of cyber conflict history.
Referenced as historical comparison for destructive malware focused on immediate operational impact.
Destructive malware/wiper referenced only as part of possible links to activity associated with Elfin.
A destructive wiper virus known for crippling Saudi Aramco in 2012, cited as evidence of Iran’s longstanding offensive cyber capability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.