Cutting Sword of Justice
Named by self givenSuspected state sponsor: Islamic Republic of IranCutting Sword of Justice is an Iranian-linked hacktivist front group that publicly claimed responsibility for the August 2012 Shamoon/Disttrack wiper attack against Saudi Aramco, one of the most destructive cyberattacks in history. The group deployed the Disttrack malware — which overwrote master boot records and destroyed data on approximately 30,000 workstations — while framing the attack as retaliation for Saudi government policies. Security researchers, the US government, and Mandiant assessed the operation was directed by Iranian state actors using the hacktivist persona for deniability. A second wave of Disttrack activity linked to the same operators struck Saudi Arabia and Gulf state organizations again in November 2016 and 2018, targeting energy, aviation, and financial sectors including Saudi Electricity Company and the General Authority of Civil Aviation. Kaspersky Lab confirmed the 2016 Disttrack variant used the same EldoS RawDisk license key as the 2012 attack, establishing operational continuity between the campaigns.
Targeted Regions
Middle EastMiddle East
Nov 2016 ~ Dec 2016
QatarQatar
Aug 2012 ~ Nov 2016
Aug 2012 ~ Nov 2016
Aug 2012 ~ Nov 2016
Aug 2012 ~ Nov 2016
Aug 2012 ~ Nov 2016
Aug 2012 ~ Nov 2016
Aug 2012 ~ Nov 2016
Aug 2012 ~ Nov 2016
Saudi ArabiaSaudi Arabia
Aug 2012 ~ Nov 2016 Aug 2012 ~ Nov 2016
Aug 2012 ~ Nov 2016 Aug 2012 ~ Nov 2016
Aug 2012 ~ Nov 2016 Aug 2012 ~ Nov 2016
Aug 2012 ~ Nov 2016 Aug 2012 ~ Nov 2016
Aug 2012 ~ Nov 2016 Aug 2012 ~ Nov 2016
Aug 2012 ~ Nov 2016 Aug 2012 ~ Nov 2016
Aug 2012 ~ Nov 2016 Aug 2012 ~ Nov 2016
Aug 2012 ~ Nov 2016 Aug 2012 ~ Nov 2016
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.