The Possible Connection Between Greenbug and Shamoon Revealed
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Malware,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/High Probability
Threat Overview
The Greenbug cyberespionage group, active since June 2016, has been using Trojan.Ismdoor, a custom information-stealing remote access Trojan (RAT), and additional hacking tools to compromise organizations in the Middle East and a Saudi organization in Australia. The group targets sectors including aviation, energy, government, investment, and education, using spearphishing emails to deliver malicious payloads hidden in RAR archives. Once opened, the Trojan opens a backdoor and collects sensitive data, potentially facilitating further attacks. Notably, the group’s activity ceased a day before the destructive W32.Disttrack.B (Shamoon) attack in November 2016, suggesting a possible connection.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Financial | Verified |
| Sector | Government Agencies and Services | Verified |
| Sector | Aerospace | Verified |
| Sector | Energy The sectors targeted by the attack were the aviation, energy, government, investment, and education sectors. | Verified |
| Sector | University | Verified |
| Region | Australia | Verified |
| Region | Bahrain | Verified |
| Region | Iran | Verified |
| Region | Iraq | Verified |
| Region | Kuwait | Verified |
| Region | Qatar | Verified |
| Region | Saudi Arabia The countries targeted by the attack were predominantly in the Middle East, specifically Saudi Arabia, Iran, Bahrain, Iraq, Qatar, Kuwait, and Turkey. Additionally, a Saudi organization in Australia was also targeted. | Verified |
| Region | Turkey | Verified |
FAQs
Frequently Asked Questions About the Greenbug Espionage Campaign and Its Links to Shamoon
A cyber espionage group called Greenbug, active since at least June 2016, ran a sustained campaign against organizations in the Middle East using a custom remote access Trojan called ISMdoor. The group targeted sectors including aviation, energy, government, investment, and education. Symantec's investigation found that Greenbug's activity on at least one compromised network stopped a day before a destructive Shamoon wiper attack hit the same organization in November 2016, raising the possibility that Greenbug had passed stolen credentials to the Shamoon attackers.
The espionage campaign was carried out by Greenbug, an Iranian-linked cyber espionage group. Symantec assessed Greenbug as a distinct actor but noted infrastructure overlaps and a suspicious timing correlation with the Shamoon group, which is also believed to have Iranian connections. The exact relationship between the two groups — whether they are the same, affiliated, or simply sharing resources — has not been definitively confirmed.
Greenbug's primary goal was espionage — gaining persistent access to targeted organizations, collecting sensitive data, and harvesting credentials. The suspected link to Shamoon suggests a secondary purpose: feeding stolen credentials to a separate group to enable destructive, follow-on attacks. This two-stage model — espionage first, destruction second — makes Greenbug particularly dangerous for organizations in critical sectors.
Greenbug's campaign was primarily focused on the Middle East, with confirmed targets in Saudi Arabia, Iran, Bahrain, Iraq, Qatar, Kuwait, and Turkey. A Saudi organization operating in Australia was also targeted, showing the group's willingness to follow targets beyond the region. The campaign ran from at least June 2016 through November 2016, spanning multiple countries and industries over several months.
Greenbug targeted organizations in the aviation, energy, government, investment, and education sectors, primarily in the Middle East. Energy and government entities appear to be the highest-priority targets, consistent with Iranian state interests in monitoring regional rivals and critical infrastructure operators. The targeting of a Saudi organization in Australia also shows the group tracks specific entities regardless of their physical location.
Greenbug sent targeted spear phishing emails containing RAR archives with malicious .chm (Compiled HTML Help) files. When a recipient opened the file, ISMdoor was silently installed, opening a backdoor and beginning data collection. The group then used credential harvesting and keylogging tools to steal account credentials from the compromised environment. In at least one case, Greenbug's access to a network appeared to be handed off — with stolen credentials likely used by the Shamoon operators to deploy a destructive wiper days later.
Energy companies, government agencies, and aviation firms in the Middle East hold strategic and economic intelligence of high value to Iranian state interests — including infrastructure vulnerabilities, procurement data, and personnel information. These organizations also tend to hold valid domain credentials and have broad internal network access, making them useful entry points for a follow-on destructive attack. Saudi Arabia in particular has been a recurring target given its geopolitical rivalry with Iran.
Organizations should block RAR and .chm file attachments at the email gateway, as these are Greenbug's primary delivery mechanism. Multi-factor authentication should be enforced on all remote access services and email portals to reduce the impact of credential theft. Endpoint detection capable of identifying RAT activity and keylogging should be deployed, especially in energy, aviation, and government environments. After any intrusion, organizations should monitor for unusual credential use and consider the possibility that stolen credentials may be leveraged by a second threat actor for a destructive follow-on attack. Maintaining tested offline backups is essential given the Shamoon connection.