Threats Feed|Unclassified|Last Updated 01/05/2026|AuthorCertfa Radar|Publish Date14/12/2018

Shamoon's Latest Version: A Growing Threat to the Middle East and European Industries

  • Actor Motivations: Sabotage
  • Attack Vectors: Malware,Wiper
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

McAfee Advanced Threat Research identified a new Shamoon Version 3 variant in December 2018, first detected when the Foundstone Emergency Incident Response team reacted to a customer breach. The variant targeted oil, gas, energy, telecom, and government organizations across the Middle East and southern Europe. Shamoon V3 operates as a modular dropper carrying three embedded components: a communication module (MNU), a wiper (LNG), and a 64-bit dropper (PIC). The wiper installs a malicious service named MaintenaceSrv and uses the ElRawDisk.sys driver to overwrite all files with garbage data before forcing a system reboot, leaving machines inoperable. The malware includes anti-forensic timestomping (faking file dates to August 2012), UAC bypass via token impersonation, and spreads laterally over ADMIN$ and Windows admin shares. The modular design means the wiper component can be detached and weaponized independently, making this variant particularly dangerous for future repurposing.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
Verified
SectorEnergy
Verified
SectorOil and Gas
Verified
SectorTelecommunication
Verified
RegionMiddle East Countries
Verified
RegionEuropean Countries
Verified

Extracted IOCs

  • 41f8cd9ac3fb6b1771177e5770537518
  • 10411f07640edcaa6104f078af09e2543aa0ca07
  • 43ed9c1309d8bb14bd62b016a5c34a2adbe45943
  • bf3e0bc893859563811e9a481fde84fe7ecd0684
  • ceb7876c01c75673699c74ff7fac64a5ca0e67a1
  • df177772518a8fcedbbc805ceed8daecc0f42fed
download

Tip: 6 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 6 file hash) to this threat have been found.

Overlaps

NewsBeefShamoon 2.0 and StoneDrill Revive Wiper Threats Across Saudi and European Targets

Source: Kaspersky - March 2017

Detection (one case): 41f8cd9ac3fb6b1771177e5770537518

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions

In December 2018, a new version of the Shamoon destructive malware — known as Version 3 — was identified during an active breach response by McAfee's incident response team. The malware hit oil, gas, energy, telecom, and government organizations in the Middle East and southern Europe, wiping all data from infected machines and leaving them completely inoperable.

In December 2018, a new version of the Shamoon destructive malware — known as Version 3 — was identified during an active breach response by McAfee's incident response team. The malware hit oil, gas, energy, telecom, and government organizations in the Middle East and southern Europe, wiping all data from infected machines and leaving them completely inoperable.

McAfee did not attribute this specific report to any particular threat actor. However, Shamoon has historically been linked to Iranian threat groups, and a follow-up McAfee report five days later attributed related December 2018 Shamoon activity to APT33 — or a group impersonating them. The presence of bugs in the V3 code suggests it may have been in a test phase, potentially indicating a newer or less experienced operator within the same threat ecosystem.

The attack was purely destructive. Shamoon V3 was designed to permanently wipe all data from targeted systems, trigger a forced reboot, and render machines completely inoperable. There was no ransomware demand or data theft involved. The goal was to cause maximum operational disruption to critical-sector organizations — consistent with the sabotage motivation seen in prior Shamoon campaigns.

Multiple organizations across the Middle East and southern Europe were hit in this wave. The campaign continued Shamoon's history of broad targeting within critical industries — previously Saudi Arabia in 2012 and 2016, now expanding to southern Europe as well. No specific count of victim organizations was disclosed, but the scope spanned multiple sectors and two geographic regions simultaneously.

The primary targets were oil, gas, and energy companies in the Middle East — the same industries Shamoon has consistently focused on since 2012. Telecom providers and government agencies were also hit in this wave. Southern European organizations appear to have been targeted as well, likely as part of the same campaign that later used European suppliers as a route into Middle Eastern primary targets.

Once on a system, Shamoon V3 drops three components from encrypted resources embedded in the dropper: a communication module, a wiper, and a 64-bit dropper variant. It then elevates its privileges by impersonating system tokens, creates a persistent autostart service (MaintenaceSrv), and spreads laterally across the network via Windows administrative shares. The wiper uses a raw disk driver (ElRawDisk.sys) to overwrite every file and disk sector with garbage data, then forces a system reboot — leaving machines with a blue screen or driver error and no path to recovery.

Energy and oil and gas infrastructure are high-value geopolitical targets — disrupting them causes broad economic and national security consequences. Shamoon has targeted this sector exclusively across all three of its major campaigns, suggesting a consistent strategic interest in degrading the energy capabilities of Middle Eastern nations. Telecom and government organizations add political and communication disruption value to the same campaign.

Organizations should maintain and regularly test offline backups — Shamoon's raw disk overwrite makes recovery impossible without them. Security teams should monitor for loading of the ElRawDisk.sys driver, creation of services with unusual or misspelled names, and modifications to the LocalAccountTokenFilterPolicy registry key. Restricting access to Windows administrative shares (ADMIN$, C$) and enabling endpoint tamper protection are also critical steps. Given Shamoon's long track record in the energy sector, threat hunting for known Shamoon indicators should be a standing practice for any organization in oil, gas, or critical infrastructure.