{
  "id": "case-saudi-aramco-shamoon",
  "slug": "saudi-aramco-shamoon-wiper",
  "title": "Saudi Aramco Shamoon Wiper Attack (Cutting Sword of Justice)",
  "summary": "Devastating state-sponsored wiper attack attributed to Iranian threat actors ('Cutting Sword of Justice') that detonated the Shamoon (Disttrack) wiper across Saudi Aramco, simultaneously wiping 35,000 workstation hard drives and overwriting Master Boot Records with an image of a burning American flag.",
  "case_number": "N/A (State-Sponsored Attribution)",
  "court": "U.S. Intelligence Community Attribution",
  "district": "National Security",
  "country": "Saudi Arabia",
  "opened_at": "2012-08-15",
  "status": "uncharged",
  "victim_sector": "Energy, Oil & Gas",
  "victim_country": "Saudi Arabia",
  "loss_amount_usd": 1000000000,
  "loss_amount_note": "Forced the world's largest oil enterprise to manage supply logistics on paper and typewriters, and purchase a substantial portion of the global hard drive market to rebuild operations.",
  "first_seen_at": "2012-08-15T08:00:00Z",
  "last_updated_at": "2026-08-18T10:00:00Z",
  "actor_slug": "oilrig-cutting-sword",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1485",
      "evidence_excerpt": "The Wiper module contained an embedded EldoS RawDisk driver to bypass Windows operating system write protection, directly overwriting raw sector bytes of the Master Boot Record with image data.",
      "evidence_locator": "CISA Alert TA12-240A: Shamoon Malware",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory TA12-240A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/ta12-240a",
      "technique_name": "Data Destruction",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1021.002",
      "evidence_excerpt": "Shamoon spread across internal subnets by utilizing administrative network shares (ADMIN$) and hardcoded domain credentials harvested from internal engineering servers.",
      "evidence_locator": "Symantec Threat Intelligence Analysis: The Shamoon Attacks",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Symantec Shamoon Intelligence Report",
      "source_url": "https://www.cisa.gov",
      "technique_name": "SMB / Windows Admin Shares",
      "tactic": "Lateral Movement"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2012-08-15",
      "description": "Shamoon wiper detonates at 8:00 AM on the Laylat al-Qadr Islamic holiday, wiping 35,000 corporate computers in under two hours."
    },
    {
      "event_type": "advisory",
      "event_date": "2012-08-27",
      "description": "US-CERT and CISA issue Alert TA12-240A warning global critical infrastructure operators of Shamoon wiper malware."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Stolen domain administrator credentials used to deploy the Shamoon (Disttrack) wiper across 35,000 corporate workstations during the Islamic holy day of Laylat al-Qadr.",
    "blast_radius": "Overwrote the Master Boot Records (MBR) and system files of 35,000 computers across Saudi Aramco in under two hours, forcing the world's largest oil enterprise to manage supply logistics on paper and purchase a major portion of the global hard drive supply.",
    "kill_chain": [
      {
        "phase": "Initial Foothold",
        "title": "Internal Domain Credential Harvesting",
        "description": "Threat actors acquired privileged network credentials on internal engineering servers, staging the multi-component wiper across internal network repositories.",
        "technical_artifacts": [
          "Hardcoded admin credentials",
          "Internal staging directories"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Automated Subnet Spread",
        "title": "Administrative Share Network Traversal",
        "description": "The wiper iterated through IP addresses across internal subnets, copying itself via administrative network shares (ADMIN$) using stolen domain credentials.",
        "technical_artifacts": [
          "ADMIN$ share writes",
          "net use commands"
        ],
        "mitre_technique_id": "T1021.002"
      },
      {
        "phase": "Raw Disk Destruction",
        "title": "EldoS RawDisk Driver MBR Overwrite",
        "description": "Shamoon deployed a legitimate, digitally signed commercial disk driver (EldoS RawDisk) to bypass operating system sector locks, overwriting disk sectors with an image of a burning American flag.",
        "technical_artifacts": [
          "EldoS RawDisk driver",
          "Disttrack wiper binary",
          "Burning flag image data"
        ],
        "mitre_technique_id": "T1485"
      }
    ],
    "defensive_takeaways": [
      "Block Bring Your Own Vulnerable Driver (BYOVD) attacks using the Microsoft Recommended Driver Blocklist.",
      "Disable ADMIN$ and default administrative file sharing across corporate workstation subnets.",
      "Maintain out-of-band golden image repositories and automated bare-metal workstation provisioning.",
      "Enforce strict behavioral endpoint alerting on raw disk write API calls."
    ]
  }
}