Netskope Threat Labs

Shamoon

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Shamoon is wiper malware first used by an Iranian group known as the Cutting Sword of Justice in 2012, with further versions observed in 2016 and 2018. It leveraged disk driver tooling to carry out data wiping at scale, and analysis has linked it to Kwampirs through shared artifacts and coding patterns. The name sometimes refers to the group using the malware as well as the malware itself.

First seen
March 2022
Last seen
October 2026
DistTrack

24 techniques across 9 tactics.

TA0002 Execution

TA0003 Persistence

TA0004 Privilege Escalation

  • T1548Abuse Elevation Control Mechanism

TA0005 Stealth

TA0007 Discovery

  • T1012Query Registry
  • T1016System Network Configuration Discovery
  • T1018Remote System Discovery
  • T1082System Information Discovery
  • T1124System Time Discovery

TA0008 Lateral Movement

TA0011 Command and Control

TA0040 Impact

TA0112 Defense Impairment

Alert Name
ByteCode-MSIL.Worm.Shamoon
Trojan.Shamoon.A
Trojan.Shamoon.B
Win32.Trojan.DistTrack
Win32.Virus.DistTrack
Win64.Trojan.DistTrack
Win64.Trojan.Shamoon