Shamoon wiper attack disrupts Saudi Aramco corporate systems
Saudi Aramco disclosed that a destructive malware attack affected its corporate computer systems and required restoration work, while stating oil production was unaffected. Public reporting described tens of thousands of workstations impacted and significant operational disruption to business IT. Vendor analyses characterize Shamoon as destructive malware designed to wipe systems.
First reported August 16, 2012Malware Campaignmed overall confidence
T1485: Shamoon is characterized by vendors as destructive malware that wipes/overwrites systems, consistent with data destruction behavior.
Mitigations
Now
Implement rapid workstation rebuild and golden image processes for destructive malware scenariosImproves recovery time when endpoints are wiped or rendered unbootable.
Soon
Segment corporate networks and restrict administrative shares and privileged credential reuseLimits the ability of destructive malware to spread and to execute widespread wiping actions.
Later
Use application allowlisting and restrict execution from user-writable locationsReduces the likelihood of malware execution and persistence on endpoints.
Detection ideas
Detect mass file overwrite/deletion and MBR/boot sector modification attempts
Alert on processes performing high-rate file deletion/overwrite across many paths or attempting to modify boot configuration/MBR-like structures.
Data sources: EDR telemetry, File integrity monitoring, Windows Security Event Logs
Alert on abnormal lateral movement and remote execution preceding destructive actions
Detect remote service creation, admin share writes, and execution of the same binary across many hosts within a short time window.
Data sources: Windows Security Event Logs, EDR telemetry, Network flow logs