THREAT DOSSIER / 04

2012 · Destructive workstation wiper

Shamoon / Disttrack

Collected system information and deployed a wiping module that overwrote boot records, partition tables and files, driving major operational disruption.

01

Entry and propagation

The initial entry vector was not officially determined; after compromise it propagated through network shares.

02

Targets

Business networks and workstations, with a documented link to the Saudi Aramco incident.

03

Impact

Unrecoverable data after wiping and disruption across a large part of a business network.

04

Defense

Separate user zones, restrict shares and administrative accounts, and detect abnormal disk-write behavior.