CASE DOSSIER uncharged

Saudi Aramco Shamoon Wiper Attack (Cutting Sword of Justice)

Docket: N/A (State-Sponsored Attribution) Court: U.S. Intelligence Community Attribution Opened: 2012-08-15 Sector: Energy, Oil & Gas

Key Facts

Status
UNCHARGED
Legal disposition
Loss Amount
$1.0 billion
Forced the world's largest oil enterprise to manage supply logistics on paper and typewriters, and purchase a substantial portion of the global hard drive market to rebuild operations.
Techniques
2
Verified mappings
Defendants
0
Named in charges
  • Legal Status: UNCHARGED in U.S. Intelligence Community Attribution.
  • Primary Target Sector: Energy, Oil & Gas.
  • Documented Financial Loss: $1.0 billion.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Devastating state-sponsored wiper attack attributed to Iranian threat actors ('Cutting Sword of Justice') that detonated the Shamoon (Disttrack) wiper across Saudi Aramco, simultaneously wiping 35,000 workstation hard drives and overwriting Master Boot Records with an image of a burning American flag.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Stolen domain administrator credentials used to deploy the Shamoon (Disttrack) wiper across 35,000 corporate workstations during the Islamic holy day of Laylat al-Qadr.

Operational & Financial Fallout

Overwrote the Master Boot Records (MBR) and system files of 35,000 computers across Saudi Aramco in under two hours, forcing the world's largest oil enterprise to manage supply logistics on paper and purchase a major portion of the global hard drive supply.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: UNCHARGED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Stolen domain administrator credentials used to deploy the Shamoon (Disttrack) wiper across 35,000 corporate workstations during the Islamic holy day of Laylat al-Qadr.

Adversary Kill Chain Flow

3 Documented Phases
1
Initial Foothold Internal Domain Credential Harvesting
MITRE ATT&CK T1078 →

Threat actors acquired privileged network credentials on internal engineering servers, staging the multi-component wiper across internal network repositories.

Artifacts & Tooling: Hardcoded admin credentials Internal staging directories
2
Automated Subnet Spread Administrative Share Network Traversal
MITRE ATT&CK T1021.002 →

The wiper iterated through IP addresses across internal subnets, copying itself via administrative network shares (ADMIN$) using stolen domain credentials.

Artifacts & Tooling: ADMIN$ share writes net use commands
3
Raw Disk Destruction EldoS RawDisk Driver MBR Overwrite
MITRE ATT&CK T1485 →

Shamoon deployed a legitimate, digitally signed commercial disk driver (EldoS RawDisk) to bypass operating system sector locks, overwriting disk sectors with an image of a burning American flag.

Artifacts & Tooling: EldoS RawDisk driver Disttrack wiper binary Burning flag image data
Real-World Blast Radius & Operational Fallout

Overwrote the Master Boot Records (MBR) and system files of 35,000 computers across Saudi Aramco in under two hours, forcing the world's largest oil enterprise to manage supply logistics on paper and purchase a major portion of the global hard drive supply.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Block Bring Your Own Vulnerable Driver (BYOVD) attacks using the Microsoft Recommended Driver Blocklist.
✓ Disable ADMIN$ and default administrative file sharing across corporate workstation subnets.
✓ Maintain out-of-band golden image repositories and automated bare-metal workstation provisioning.
✓ Enforce strict behavioral endpoint alerting on raw disk write API calls.

Procedural & Incident Timeline

2012-08-15 incident

Shamoon wiper detonates at 8:00 AM on the Laylat al-Qadr Islamic holiday, wiping 35,000 corporate computers in under two hours.

2012-08-27 advisory

US-CERT and CISA issue Alert TA12-240A warning global critical infrastructure operators of Shamoon wiper malware.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1485 Data Destruction
Impact
"The Wiper module contained an embedded EldoS RawDisk driver to bypass Windows operating system write protection, directly overwriting raw sector bytes of the Master Boot Record with image data." CISA Alert TA12-240A: Shamoon Malware reviewed
T1021.002 SMB / Windows Admin Shares
Lateral Movement
"Shamoon spread across internal subnets by utilizing administrative network shares (ADMIN$) and hardcoded domain credentials harvested from internal engineering servers." Symantec Threat Intelligence Analysis: The Shamoon Attacks reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Saudi Aramco Shamoon Wiper Attack (Cutting Sword of Justice), No. N/A (State-Sponsored Attribution) (U.S. Intelligence Community Attribution 2012), https://cybercaselibrary.com/cases/saudi-aramco-shamoon-wiper/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/saudi-aramco-shamoon-wiper" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>