Saudi Aramco Shamoon Wiper Attack (Cutting Sword of Justice)
Key Facts
- Legal Status: UNCHARGED in U.S. Intelligence Community Attribution.
- Primary Target Sector: Energy, Oil & Gas.
- Documented Financial Loss: $1.0 billion.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Stolen domain administrator credentials used to deploy the Shamoon (Disttrack) wiper across 35,000 corporate workstations during the Islamic holy day of Laylat al-Qadr.
Operational & Financial Fallout
Overwrote the Master Boot Records (MBR) and system files of 35,000 computers across Saudi Aramco in under two hours, forcing the world's largest oil enterprise to manage supply logistics on paper and purchase a major portion of the global hard drive supply.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Stolen domain administrator credentials used to deploy the Shamoon (Disttrack) wiper across 35,000 corporate workstations during the Islamic holy day of Laylat al-Qadr.
Adversary Kill Chain Flow
3 Documented PhasesThreat actors acquired privileged network credentials on internal engineering servers, staging the multi-component wiper across internal network repositories.
The wiper iterated through IP addresses across internal subnets, copying itself via administrative network shares (ADMIN$) using stolen domain credentials.
Shamoon deployed a legitimate, digitally signed commercial disk driver (EldoS RawDisk) to bypass operating system sector locks, overwriting disk sectors with an image of a burning American flag.
Overwrote the Master Boot Records (MBR) and system files of 35,000 computers across Saudi Aramco in under two hours, forcing the world's largest oil enterprise to manage supply logistics on paper and purchase a major portion of the global hard drive supply.
Procedural & Incident Timeline
Shamoon wiper detonates at 8:00 AM on the Laylat al-Qadr Islamic holiday, wiping 35,000 corporate computers in under two hours.
US-CERT and CISA issue Alert TA12-240A warning global critical infrastructure operators of Shamoon wiper malware.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1485 | Data Destruction Impact | "The Wiper module contained an embedded EldoS RawDisk driver to bypass Windows operating system write protection, directly overwriting raw sector bytes of the Master Boot Record with image data." | CISA Alert TA12-240A: Shamoon Malware | reviewed |
| T1021.002 | SMB / Windows Admin Shares Lateral Movement | "Shamoon spread across internal subnets by utilizing administrative network shares (ADMIN$) and hardcoded domain credentials harvested from internal engineering servers." | Symantec Threat Intelligence Analysis: The Shamoon Attacks | reviewed |