Shamoon 2: The Return of Disttrack's Destructive Force in Saudi Arabia
- Actor Motivations: Sabotage
- Attack Vectors: Dropper,Malware,Trojan,Wiper,Worms
- Attack Complexity: Medium
- Threat Risk: High Impact/High Probability
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Energy | Verified |
| Region | Saudi Arabia | Verified |
Extracted IOCs
- 128fa5815c6fee68463b18051c1a1ccdf28c599ce321691686b1efa4838a2acd
- 394a7ebad5dfc13d6c75945a61063470dc3b68f7a207613b79ef000e1990909b
- 4744df6ac02ff0a3f9ad0bf47b15854bbebb73c936dd02f7c79293a2828406f6
- 47bb36cd2832a18b5ae951cf5a7d44fba6d8f5dca0a372392d40f51d1fe1ac34
- 5a826b4fa10891cf63aae832fc645ce680a483b915c608ca26cedbb173b1b80a
- 61c1c8fc8b268127751ac565ed4abd6bdab8d2d0f2ff6074291b2d54b0228842
- 772ceedbc2cacf7b16ae967de310350e42aa47e5cef19f4423220d41501d86a5
- c7fc1f9c2bed748b50a599ee2fa609eb7c9ddaeb9cd16633ba0d10cf66891d8a
Tip: 8 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 8 file hash) to this threat have been found.
Overlaps
Source: Kaspersky - March 2017
Detection (seven cases): 128fa5815c6fee68463b18051c1a1ccdf28c599ce321691686b1efa4838a2acd, 394a7ebad5dfc13d6c75945a61063470dc3b68f7a207613b79ef000e1990909b, 4744df6ac02ff0a3f9ad0bf47b15854bbebb73c936dd02f7c79293a2828406f6, 47bb36cd2832a18b5ae951cf5a7d44fba6d8f5dca0a372392d40f51d1fe1ac34, 61c1c8fc8b268127751ac565ed4abd6bdab8d2d0f2ff6074291b2d54b0228842, 772ceedbc2cacf7b16ae967de310350e42aa47e5cef19f4423220d41501d86a5, c7fc1f9c2bed748b50a599ee2fa609eb7c9ddaeb9cd16633ba0d10cf66891d8a
Source: Blackberry - February 2017
Detection (six cases): 128fa5815c6fee68463b18051c1a1ccdf28c599ce321691686b1efa4838a2acd, 394a7ebad5dfc13d6c75945a61063470dc3b68f7a207613b79ef000e1990909b, 47bb36cd2832a18b5ae951cf5a7d44fba6d8f5dca0a372392d40f51d1fe1ac34, 61c1c8fc8b268127751ac565ed4abd6bdab8d2d0f2ff6074291b2d54b0228842, 772ceedbc2cacf7b16ae967de310350e42aa47e5cef19f4423220d41501d86a5, c7fc1f9c2bed748b50a599ee2fa609eb7c9ddaeb9cd16633ba0d10cf66891d8a
Source: Vin Ransomware - February 2017
Detection (six cases): 128fa5815c6fee68463b18051c1a1ccdf28c599ce321691686b1efa4838a2acd, 394a7ebad5dfc13d6c75945a61063470dc3b68f7a207613b79ef000e1990909b, 47bb36cd2832a18b5ae951cf5a7d44fba6d8f5dca0a372392d40f51d1fe1ac34, 5a826b4fa10891cf63aae832fc645ce680a483b915c608ca26cedbb173b1b80a, 61c1c8fc8b268127751ac565ed4abd6bdab8d2d0f2ff6074291b2d54b0228842, c7fc1f9c2bed748b50a599ee2fa609eb7c9ddaeb9cd16633ba0d10cf66891d8a
Source: Palo Alto Networks - January 2017
Detection (one case): 5a826b4fa10891cf63aae832fc645ce680a483b915c608ca26cedbb173b1b80a
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
The Updated Disttrack Destructive Campaign
Cybersecurity researchers recently discovered an updated version of a highly destructive malware known as Disttrack. This malware was deployed against at least one organization in Saudi Arabia with the sole purpose of wiping computer hard drives and rendering the systems completely unusable.
While a specific group name is not explicitly confirmed, the attackers perfectly mirror the tactics of the threat actors behind the infamous "Shamoon" attacks of 2012. They are known for utilizing politically themed imagery and timing their attacks during local holidays or weekends to maximize the damage while IT staff are away.
The attack was designed entirely for sabotage and data destruction rather than espionage or stealing money. The attackers deliberately broke the malware's ability to "call home" to a control server, proving they only wanted to unleash it on the network to cause permanent, automated damage.
The current investigation identified at least one targeted organization in Saudi Arabia, but the malware is built to automatically spread to every connected computer it can find on a local network. A similar attack carried out by this group four years ago successfully destroyed over 30,000 systems in a single incident.
The attack specifically targeted an organization in Saudi Arabia, which aligns with the perpetrators' historical focus on disrupting the Saudi energy sector. The attackers specifically targeted internal networks by utilizing passwords and domain names that belonged exclusively to the victim organization.
The attackers used stolen, high-level administrative passwords to quietly log into the network and automatically copy the malware from computer to computer. Once a specific date and time was reached—strategically set for Thursday evening, the malware triggered a wiping tool that permanently erased the computers by overwriting their files with a political photograph.
The attackers appear to be politically motivated, utilizing devastating cyberattacks to make a statement or cause massive operational disruption to major Saudi infrastructure. This is highlighted by their deliberate use of provocative or highly publicized political images, such as a photograph of a Syrian refugee, to overwrite the victims' data.
Organizations should immediately change their administrative passwords and ensure strict limits are placed on who can access sensitive network areas. Additionally, security teams should actively monitor for unauthorized changes to local computer security settings and block the unapproved installation of system drivers.
This is a highly targeted threat rather than a widespread virus found on the public internet. The malware relies on network names and passwords that were explicitly stolen from the victim ahead of time, meaning it was custom-built for that specific environment.