Showing posts with label Shamoon. Show all posts
Showing posts with label Shamoon. Show all posts

Tuesday, April 18, 2017

Shamoon2 Overwrites and Attacks Saudi Targets


Wapack Labs's research has uncovered Iranian actors using Shamoon2 against Saudi infrastructure and industry targets. Shamoon2 renders infected systems inoperable by overwriting the Master Boot Records (MBR). The actors responsible are using commercially available kernel drivers, which may indicate a lack of experience with Windows kernel development. Though, there is evidence indicating the malware was designed by reverse engineering malware attributed to a nation-state, suggesting that their skills are improving. Further attacks against Saudi-related targets using the Shamoon-family of malware are highly likely...READ MORE

Wapack Labs has cataloged and reported extensively on malware in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Thursday, January 26, 2017

Shamoon and Essex Shipping


On 17 January 2017 the Saudi Arabia Computer Emergency Response Team (CERT), Abdulrahman al-Friah, confirmed that close to 22 businesses in Saudi Arabia were affected by the Shamoon malware virus. Shamoon is alleged to have been created in Iran, and is the same wiper malware that hit Saudi Aramco in 2012. Some are identifying the malware as: Shimon 2. Among the companies affected was Essex Shipping.

Wapack Labs has reported on cyber threats to the maritime sector in the past. An archive of related reporting can be found in the Red Sky Alliance portal in the Red Sky Alliance Portal.

TLP: GREEN
ACTOR TYPE: (V)
SERIAL: TR-018-2017
COUNTRIES: SA, GB
REPORT DATE: 20170125