Shamoon

S0140

Malware.View on attack.mitre.org

About this malware

Shamoon is wiper malware that was first used by an Iranian group known as the "Cutting Sword of Justice" in 2012. Other versions known as Shamoon 2 and Shamoon 3 were observed in 2016 and 2018. Shamoon has also been seen leveraging RawDisk and Filerase to carry out data wiping tasks. Analysis has linked Shamoon with Kwampirs based on multiple shared artifacts and coding patterns. The term Shamoon is sometimes used to refer to the group using the malware as well as the malware itself.

Techniques used24

Procedure examples24

TechniqueProcedure example
T1012
Query Registry

Shamoon queries several Registry keys to identify hard disk partitions to overwrite.

T1016
System Network Configuration Discovery

Shamoon obtains the target's IP address and local network segment.

T1018
Remote System Discovery

Shamoon scans the C-class subnet of the IPs on the victim's interfaces.

T1021.002
SMB/Windows Admin Shares

Shamoon accesses network share(s), enables share access to the target device, copies an executable payload to the target system, and uses a Scheduled Task/Job to execute the malware.

T1027
Obfuscated Files or Information

Shamoon contains base64-encoded strings.

T1036.004
Masquerade Task or Service

Shamoon creates a new service named “ntssrv” that attempts to appear legitimate; the service's display name is “Microsoft Network Realtime Inspection Service” and its description is “Helps guard against time change attempts targeting known and newly discovered vulnerabilities in network time protocols.” Newer versions create the "MaintenaceSrv" service, which misspells the word "maintenance."

T1053.005
Scheduled Task

Shamoon copies an executable payload to the target system by using SMB/Windows Admin Shares and then scheduling an unnamed task to execute the malware.

T1070.006
Timestomp

Shamoon can change the modified time for files to evade forensic detection.

T1071.001
Web Protocols

Shamoon has used HTTP for C2.

T1078.002
Domain Accounts

If Shamoon cannot access shares using current privileges, it attempts access using hard coded, domain-specific credentials gathered earlier in the intrusion.

T1082
System Information Discovery

Shamoon obtains the victim's operating system version and keyboard layout and sends the information to the C2 server.

T1105
Ingress Tool Transfer

Shamoon can download an executable to run on the victim.

T1112
Modify Registry

Once Shamoon has access to a network share, it enables the RemoteRegistry service on the target system. It will then connect to the system with RegConnectRegistryW and modify the Registry to disable UAC remote restrictions by setting SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy to 1.

T1124
System Time Discovery

Shamoon obtains the system time and will only activate if it is greater than a preset date.

T1134.001
Token Impersonation/Theft

Shamoon can impersonate tokens using LogonUser, ImpersonateLoggedOnUser, and ImpersonateNamedPipeClient.

View all 24 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References5

  1. Cylera Kwampirs 2022 Open source
    Pablo Rincón Crespo. (2022, January). The link between Kwampirs (Orangeworm) and Shamoon APTs. Retrieved February 8, 2024.
  2. FireEye Shamoon Nov 2016 Open source
    FireEye. (2016, November 30). FireEye Responds to Wave of Destructive Cyber Attacks in Gulf Region. Retrieved November 17, 2024.
  3. Palo Alto Shamoon Nov 2016 Open source
    Falcone, R.. (2016, November 30). Shamoon 2: Return of the Disttrack Wiper. Retrieved January 11, 2017.
  4. Symantec Shamoon 2012 Open source
    Symantec. (2012, August 16). The Shamoon Attacks. Retrieved March 14, 2019.
  5. Unit 42 Shamoon3 2018 Open source
    Falcone, R. (2018, December 13). Shamoon 3 Targets Oil and Gas Organization. Retrieved March 14, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.