Malware.View on attack.mitre.org
Shamoon is wiper malware that was first used by an Iranian group known as the "Cutting Sword of Justice" in 2012. Other versions known as Shamoon 2 and Shamoon 3 were observed in 2016 and 2018. Shamoon has also been seen leveraging RawDisk and Filerase to carry out data wiping tasks. Analysis has linked Shamoon with Kwampirs based on multiple shared artifacts and coding patterns. The term Shamoon is sometimes used to refer to the group using the malware as well as the malware itself.
| Technique | Procedure example |
|---|---|
| T1012 Query Registry |
Shamoon queries several Registry keys to identify hard disk partitions to overwrite. |
| T1016 System Network Configuration Discovery |
Shamoon obtains the target's IP address and local network segment. |
| T1018 Remote System Discovery |
Shamoon scans the C-class subnet of the IPs on the victim's interfaces. |
| T1021.002 SMB/Windows Admin Shares |
Shamoon accesses network share(s), enables share access to the target device, copies an executable payload to the target system, and uses a Scheduled Task/Job to execute the malware. |
| T1027 Obfuscated Files or Information |
Shamoon contains base64-encoded strings. |
| T1036.004 Masquerade Task or Service |
Shamoon creates a new service named “ntssrv” that attempts to appear legitimate; the service's display name is “Microsoft Network Realtime Inspection Service” and its description is “Helps guard against time change attempts targeting known and newly discovered vulnerabilities in network time protocols.” Newer versions create the "MaintenaceSrv" service, which misspells the word "maintenance." |
| T1053.005 Scheduled Task |
Shamoon copies an executable payload to the target system by using SMB/Windows Admin Shares and then scheduling an unnamed task to execute the malware. |
| T1070.006 Timestomp |
Shamoon can change the modified time for files to evade forensic detection. |
| T1071.001 Web Protocols |
Shamoon has used HTTP for C2. |
| T1078.002 Domain Accounts |
If Shamoon cannot access shares using current privileges, it attempts access using hard coded, domain-specific credentials gathered earlier in the intrusion. |
| T1082 System Information Discovery |
Shamoon obtains the victim's operating system version and keyboard layout and sends the information to the C2 server. |
| T1105 Ingress Tool Transfer |
Shamoon can download an executable to run on the victim. |
| T1112 Modify Registry |
Once Shamoon has access to a network share, it enables the RemoteRegistry service on the target system. It will then connect to the system with RegConnectRegistryW and modify the Registry to disable UAC remote restrictions by setting |
| T1124 System Time Discovery |
Shamoon obtains the system time and will only activate if it is greater than a preset date. |
| T1134.001 Token Impersonation/Theft |
Shamoon can impersonate tokens using |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.