APT33 Suspected in Latest Shamoon Attacks Targeting Middle East and European Energy Sector
- Actor Motivations: Sabotage
- Attack Vectors: Wiper,Spear Phishing,Supply Chain Compromise
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
McAfee Advanced Threat Research analysts attribute a late-2018 wave of Shamoon destructive attacks to APT33, or a group impersonating them. The campaign used a modular .NET toolkit — comprising OCLC.exe, spreader.exe, SpreaderPsexec.exe, and a new file-erasure wiper called Filerase — alongside Shamoon Version 3. Initial access was gained through spear-phishing websites that mimicked legitimate energy-sector job portals, harvesting corporate credentials from targeted organizations in the Middle East and Europe as early as August 2018. Attackers then used those credentials to move laterally and deploy wipers across victim networks in a supply-chain-style operation, with the wiper execution stage reached in December 2018.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Energy | Verified |
| Region | Middle East Countries | Verified |
| Region | European Countries | Verified |
Extracted IOCs
- 0104e42d1d6522f6170ca4aa42fcbf70f7390a74
- 3eab7112e94f9ec1e07b9ae4696052a7cf123bba
- cb8faa97e94c3c60b680e28eb6a2d3910d1ce466
- f972d776d7dabf9f978dc4cc4f69d88e715541ff
Tip: 4 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 4 file hash) to this threat have been found.
FAQs
Frequently Asked Questions
In December 2018, a wave of destructive cyberattacks hit energy-sector companies in the Middle East and Europe. The attackers deployed Shamoon Version 3 — a data-wiping malware — alongside a new file-erasure tool called Filerase. Together, these tools deleted files across targeted networks, causing significant operational disruption. The groundwork for the attack had been laid months earlier, with credential harvesting starting as far back as August 2018.
McAfee researchers concluded that APT33 — an Iranian threat group — or a group deliberately impersonating APT33, is likely responsible for the attacks. The attribution is based on analysis of three generations of the Shamoon wiper, tooling overlaps, and behavioral patterns consistent with prior APT33 campaigns. The source notes the possibility that another actor may have used APT33 tradecraft to obscure their identity.
The primary goal was sabotage — rendering targeted organizations' systems inoperable by permanently destroying data. The attackers were not after financial gain or intelligence. Their aim was to cause maximum operational disruption, as seen in previous Shamoon campaigns. The inclusion of Quranic text inside the wiper code suggests a politically or ideologically motivated dimension to the operation.
The campaign targeted multiple organizations across the Middle East and Europe, with a focus on the energy sector. Shamoon Version 3 extended the reach of prior campaigns — which had concentrated on Saudi Arabia — by going after Middle Eastern targets through their European suppliers, introducing a supply-chain dimension. While the exact number of victim organizations was not disclosed, the campaign affected multiple companies across both regions.
The energy sector was the primary target. The fake job-offering websites used to harvest credentials were largely themed around energy-sector employment. European companies appear to have been targeted indirectly, as suppliers to Middle Eastern energy organizations, rather than as primary targets in their own right. No specific company names were disclosed in the McAfee report.
The attackers first set up fake websites mimicking energy-sector job portals to collect corporate usernames and passwords. Victims who visited these sites either executed malicious HTML application files — which silently ran PowerShell scripts to download additional payloads — or entered their credentials directly. With those credentials in hand, the attackers logged into victim networks and used a .NET toolkit to spread the Shamoon and Filerase wipers to targeted machines, ultimately triggering the destructive payload.
Energy infrastructure — particularly in the Middle East — is a high-value geopolitical target. Disrupting oil and gas operations can have broad economic and political consequences for nation-states. APT33 has a documented history of targeting aviation and energy sectors, making these organizations a consistent focus. European suppliers are attractive as softer entry points into otherwise well-defended primary targets.
Organizations should enforce multi-factor authentication on all remote access points and external services so that stolen passwords alone cannot grant access. IT teams should monitor for unusual use of PsExec and administrative shares, block PowerShell running with hidden-window flags, and maintain offline backups since wiper malware makes recovery impossible without them. Security teams should also audit third-party supplier access and apply the same security standards to the supply chain as to internal systems.