Threats Feed|Cutting Sword of Justice|Last Updated 28/01/2026|AuthorCertfa Radar|Publish Date01/12/2016

Shamoon 2.0 Resurfaces in the Gulf States with Enhanced Cyberattack Tactics

  • Actor Motivations: Sabotage
  • Attack Vectors: Malware,Wiper
  • Attack Complexity: Very High
  • Threat Risk: High Impact/High Probability

Threat Overview

In mid-November 2016, Mandiant responded to the Shamoon 2.0 malware attack targeting organizations in the Gulf states, marking the return of the suspected Iranian hacker group "Cutting Sword of Justice." This updated version of the 2012 Shamoon malware features embedded credentials, suggesting previous targeted intrusions for credential harvesting. Shamoon 2.0 performs subnet scanning, uses domain-specific credentials for unauthorized access, modifies system registries, and schedules tasks for execution. Its payload involves overwriting system files and wiping boot records, notably shifting imagery from a burning U.S. flag to a photograph of Alan Kurdi, symbolizing a devastating critique through cyber vandalism.

Detected Targets

TypeDescriptionConfidence
RegionMiddle East Countries
Verified

Extracted IOCs

  • 10de241bb7028788a8f278e27a4e335f
  • 76c643ab29d497317085e5db8c799960
  • ac4d91e919a3ef210a59acab0dbb9ab5
  • b5d2a4d8ba015f3e89ade820c5840639
  • c843046e54b755ec63ccb09d0a689674
download

Tip: 5 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 5 file hash) to this threat have been found.

Overlaps

NewsBeefShamoon 2.0 and StoneDrill Revive Wiper Threats Across Saudi and European Targets

Source: Kaspersky - March 2017

Detection (two cases): ac4d91e919a3ef210a59acab0dbb9ab5, c843046e54b755ec63ccb09d0a689674

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

About Affiliation
Cutting Sword of Justice
Cutting Sword of Justice is an Iranian-linked hacktivist front group that publicly claimed responsibility for the August 2012 Shamoon/Disttrack wiper attack against Saudi Aramco, one of the most destructive cyberattacks in history. The group deployed the Disttrack malware — which overwrote master boot records and destroyed data on approximately 30,000 workstations — while framing the attack as retaliation for Saudi government policies. Security researchers, the US government, and Mandiant assessed the operation was directed by Iranian state actors using the hacktivist persona for deniability. A second wave of Disttrack activity linked to the same operators struck Saudi Arabia and Gulf state organizations again in November 2016 and 2018, targeting energy, aviation, and financial sectors including Saudi Electricity Company and the General Authority of Civil Aviation. Kaspersky Lab confirmed the 2016 Disttrack variant used the same EldoS RawDisk license key as the 2012 attack, establishing operational continuity between the campaigns.
View Cutting Sword of Justice's Insights