First reportedAugust 16, 2012
ActivityAugust 15, 2012
Last updatedFeb 2, 2026, 12:00 AM UTC
Record confidencemed

Key facts

Affected

  • Saudi Aramco (corporate IT environment)
  • Employees and business processes relying on Aramco corporate systems

Initial access

  • unknown

Impact

  • service_disruption
  • financial_loss
  • unknown

Attribution

unknown low confidence

Public sources describe the incident and malware family but do not provide definitive attribution in the cited materials.

CVEs and ATT&CK

CVEs

ATT&CK techniques

  • T1485: Shamoon is characterized by vendors as destructive malware that wipes/overwrites systems, consistent with data destruction behavior.

Mitigations

Now

  • Implement rapid workstation rebuild and golden image processes for destructive malware scenariosImproves recovery time when endpoints are wiped or rendered unbootable.

Soon

  • Segment corporate networks and restrict administrative shares and privileged credential reuseLimits the ability of destructive malware to spread and to execute widespread wiping actions.

Later

  • Use application allowlisting and restrict execution from user-writable locationsReduces the likelihood of malware execution and persistence on endpoints.

Detection ideas

Detect mass file overwrite/deletion and MBR/boot sector modification attempts

Alert on processes performing high-rate file deletion/overwrite across many paths or attempting to modify boot configuration/MBR-like structures.

Data sources: EDR telemetry, File integrity monitoring, Windows Security Event Logs

Alert on abnormal lateral movement and remote execution preceding destructive actions

Detect remote service creation, admin share writes, and execution of the same binary across many hosts within a short time window.

Data sources: Windows Security Event Logs, EDR telemetry, Network flow logs

Sources