Threats Feed|Unclassified|Last Updated 18/05/2026|AuthorCertfa Radar|Publish Date16/08/2012

Shamoon Malware Targets Systems for Data Destruction

  • Actor Motivations: Sabotage
  • Attack Vectors: Dropper,Trojan,Wiper
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

The report details a malware resembling the infamous wiper used in the 2012 Iranian cyber incidents, though it's identified as a copycat rather than the original. It destroys data by wiping the Master Boot Record (MBR) using a signed disk driver. The malware encrypts its resources to avoid detection and collects information about potentially important files on infected systems for targeted destruction. Despite similarities to past cyberattacks, its use of different service names and wiping patterns, along with the lack of financial motives, suggests the involvement of "script kiddies" rather than sophisticated cybercriminals. The exact origin or purpose, including targeted countries or sectors, remains unspecified.

Detected Targets

TypeDescriptionConfidence
RegionMiddle East Countries
High

FAQs

Shamoon Wiper Malware

Security researchers intercepted a new piece of destructive software known as "Shamoon" that is designed to permanently erase data on infected computers. It attempts to copy the methods of older, infamous cyberattacks to destroy computer systems rather than steal from them.

Analysts believe the attackers are "copycat" hackers inspired by the 2012 computer-wiping incidents in Iran, rather than advanced state-sponsored actors. The name "Shamoon" was found in the software's code, but the exact identities of the individuals remain unknown.

Unlike most cybercrimes that focus on financial theft, the primary goal of this attack is purely destructive. The malware scans the computer for valuable personal files and then permanently destroys the computer's ability to turn on by wiping its hard drive.

Currently, the threat is not widespread across the internet. Security monitoring shows only a couple of isolated hits globally, which were likely triggered by other security researchers safely testing the files.

While no specific industry is definitively named, the malware actively targets standard user files like documents, downloads, pictures, music, and videos. Analysts conclude it is being used in highly focused, targeted attacks rather than a broad internet sweep.

The attackers trick the system by using a legitimate, digitally signed security tool to bypass normal computer defenses. Once inside, the program acts in two stages, potentially spreading to other computers on the network before triggering its destructive wiping function.

Attackers deploying destructive malware typically seek to cause severe operational disruption, chaos, or reputational damage to specific organizations, rather than attempting to quietly steal data for monetary profit.

Organizations should ensure their antivirus software is up to date to catch the known identifiers for the Shamoon malware. Additionally, maintaining secure, offline backups of all critical data is the most essential step to recover quickly from any destructive attack.

This is a highly targeted issue. Experts have confirmed that cases of destructive malware like this are rare and are not currently spreading broadly to the general public.