ATT&CKReferencesFireEye Shamoon Nov 2016

FireEye Shamoon Nov 2016

FireEye. (2016, November 30). FireEye Responds to Wave of Destructive Cyber Attacks in Gulf Region. Retrieved November 17, 2024.

Open the source

Techniques2

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1018
Remote System Discovery
MalwareShamoon

Shamoon scans the C-class subnet of the IPs on the victim's interfaces.

T1021.002
SMB/Windows Admin Shares
MalwareShamoon

Shamoon accesses network share(s), enables share access to the target device, copies an executable payload to the target system, and uses a Scheduled Task/Job to execute the malware.

T1053.005
Scheduled Task
MalwareShamoon

Shamoon copies an executable payload to the target system by using SMB/Windows Admin Shares and then scheduling an unnamed task to execute the malware.

T1078.002
Domain Accounts
MalwareShamoon

If Shamoon cannot access shares using current privileges, it attempts access using hard coded, domain-specific credentials gathered earlier in the intrusion.

T1112
Modify Registry
MalwareShamoon

Once Shamoon has access to a network share, it enables the RemoteRegistry service on the target system. It will then connect to the system with RegConnectRegistryW and modify the Registry to disable UAC remote restrictions by setting SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy to 1.

T1485
Data Destruction
MalwareShamoon

Shamoon attempts to overwrite operating system files and disk structures with image files. In a later variant, randomly generated data was used for data overwrites.

T1561.002
Disk Structure Wipe
MalwareShamoon

Shamoon has been seen overwriting features of disk structure such as the MBR.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.