Threats Feed|Cutting Sword of Justice|Last Updated 19/05/2026|AuthorCertfa Radar|Publish Date30/11/2016

Shamoon 2: The Return of Disttrack's Destructive Force in Saudi Arabia

  • Actor Motivations: Sabotage
  • Attack Vectors: Dropper,Malware,Trojan,Wiper,Worms
  • Attack Complexity: Medium
  • Threat Risk: High Impact/High Probability

Detected Targets

TypeDescriptionConfidence
SectorEnergy
Verified
RegionSaudi Arabia
Verified

Extracted IOCs

  • 128fa5815c6fee68463b18051c1a1ccdf28c599ce321691686b1efa4838a2acd
  • 394a7ebad5dfc13d6c75945a61063470dc3b68f7a207613b79ef000e1990909b
  • 4744df6ac02ff0a3f9ad0bf47b15854bbebb73c936dd02f7c79293a2828406f6
  • 47bb36cd2832a18b5ae951cf5a7d44fba6d8f5dca0a372392d40f51d1fe1ac34
  • 5a826b4fa10891cf63aae832fc645ce680a483b915c608ca26cedbb173b1b80a
  • 61c1c8fc8b268127751ac565ed4abd6bdab8d2d0f2ff6074291b2d54b0228842
  • 772ceedbc2cacf7b16ae967de310350e42aa47e5cef19f4423220d41501d86a5
  • c7fc1f9c2bed748b50a599ee2fa609eb7c9ddaeb9cd16633ba0d10cf66891d8a
download

Tip: 8 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 8 file hash) to this threat have been found.

Overlaps

NewsBeefShamoon 2.0 and StoneDrill Revive Wiper Threats Across Saudi and European Targets

Source: Kaspersky - March 2017

Detection (seven cases): 128fa5815c6fee68463b18051c1a1ccdf28c599ce321691686b1efa4838a2acd, 394a7ebad5dfc13d6c75945a61063470dc3b68f7a207613b79ef000e1990909b, 4744df6ac02ff0a3f9ad0bf47b15854bbebb73c936dd02f7c79293a2828406f6, 47bb36cd2832a18b5ae951cf5a7d44fba6d8f5dca0a372392d40f51d1fe1ac34, 61c1c8fc8b268127751ac565ed4abd6bdab8d2d0f2ff6074291b2d54b0228842, 772ceedbc2cacf7b16ae967de310350e42aa47e5cef19f4423220d41501d86a5, c7fc1f9c2bed748b50a599ee2fa609eb7c9ddaeb9cd16633ba0d10cf66891d8a

Cutting Sword of JusticeDisttrack Malware Decimates Saudi Critical Infrastructure

Source: Blackberry - February 2017

Detection (six cases): 128fa5815c6fee68463b18051c1a1ccdf28c599ce321691686b1efa4838a2acd, 394a7ebad5dfc13d6c75945a61063470dc3b68f7a207613b79ef000e1990909b, 47bb36cd2832a18b5ae951cf5a7d44fba6d8f5dca0a372392d40f51d1fe1ac34, 61c1c8fc8b268127751ac565ed4abd6bdab8d2d0f2ff6074291b2d54b0228842, 772ceedbc2cacf7b16ae967de310350e42aa47e5cef19f4423220d41501d86a5, c7fc1f9c2bed748b50a599ee2fa609eb7c9ddaeb9cd16633ba0d10cf66891d8a

UnclassifiedShamoon 2.0: Elevated Threat with Advanced Evasion Techniques in the Middle East

Source: Vin Ransomware - February 2017

Detection (six cases): 128fa5815c6fee68463b18051c1a1ccdf28c599ce321691686b1efa4838a2acd, 394a7ebad5dfc13d6c75945a61063470dc3b68f7a207613b79ef000e1990909b, 47bb36cd2832a18b5ae951cf5a7d44fba6d8f5dca0a372392d40f51d1fe1ac34, 5a826b4fa10891cf63aae832fc645ce680a483b915c608ca26cedbb173b1b80a, 61c1c8fc8b268127751ac565ed4abd6bdab8d2d0f2ff6074291b2d54b0228842, c7fc1f9c2bed748b50a599ee2fa609eb7c9ddaeb9cd16633ba0d10cf66891d8a

UnclassifiedData Wiping and Network Intrusion: The Second Wave of Shamoon 2 Attacks

Source: Palo Alto Networks - January 2017

Detection (one case): 5a826b4fa10891cf63aae832fc645ce680a483b915c608ca26cedbb173b1b80a

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

The Updated Disttrack Destructive Campaign

Cybersecurity researchers recently discovered an updated version of a highly destructive malware known as Disttrack. This malware was deployed against at least one organization in Saudi Arabia with the sole purpose of wiping computer hard drives and rendering the systems completely unusable.

While a specific group name is not explicitly confirmed, the attackers perfectly mirror the tactics of the threat actors behind the infamous "Shamoon" attacks of 2012. They are known for utilizing politically themed imagery and timing their attacks during local holidays or weekends to maximize the damage while IT staff are away.

The attack was designed entirely for sabotage and data destruction rather than espionage or stealing money. The attackers deliberately broke the malware's ability to "call home" to a control server, proving they only wanted to unleash it on the network to cause permanent, automated damage.

The current investigation identified at least one targeted organization in Saudi Arabia, but the malware is built to automatically spread to every connected computer it can find on a local network. A similar attack carried out by this group four years ago successfully destroyed over 30,000 systems in a single incident.

The attack specifically targeted an organization in Saudi Arabia, which aligns with the perpetrators' historical focus on disrupting the Saudi energy sector. The attackers specifically targeted internal networks by utilizing passwords and domain names that belonged exclusively to the victim organization.

The attackers used stolen, high-level administrative passwords to quietly log into the network and automatically copy the malware from computer to computer. Once a specific date and time was reached—strategically set for Thursday evening, the malware triggered a wiping tool that permanently erased the computers by overwriting their files with a political photograph.

The attackers appear to be politically motivated, utilizing devastating cyberattacks to make a statement or cause massive operational disruption to major Saudi infrastructure. This is highlighted by their deliberate use of provocative or highly publicized political images, such as a photograph of a Syrian refugee, to overwrite the victims' data.

Organizations should immediately change their administrative passwords and ensure strict limits are placed on who can access sensitive network areas. Additionally, security teams should actively monitor for unauthorized changes to local computer security settings and block the unapproved installation of system drivers.

This is a highly targeted threat rather than a widespread virus found on the public internet. The malware relies on network names and passwords that were explicitly stolen from the victim ahead of time, meaning it was custom-built for that specific environment.

About Affiliation
Cutting Sword of Justice
Cutting Sword of Justice is an Iranian-linked hacktivist front group that publicly claimed responsibility for the August 2012 Shamoon/Disttrack wiper attack against Saudi Aramco, one of the most destructive cyberattacks in history. The group deployed the Disttrack malware — which overwrote master boot records and destroyed data on approximately 30,000 workstations — while framing the attack as retaliation for Saudi government policies. Security researchers, the US government, and Mandiant assessed the operation was directed by Iranian state actors using the hacktivist persona for deniability. A second wave of Disttrack activity linked to the same operators struck Saudi Arabia and Gulf state organizations again in November 2016 and 2018, targeting energy, aviation, and financial sectors including Saudi Electricity Company and the General Authority of Civil Aviation. Kaspersky Lab confirmed the 2016 Disttrack variant used the same EldoS RawDisk license key as the 2012 attack, establishing operational continuity between the campaigns.
View Cutting Sword of Justice's Insights