Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Security Management //

SOC

12/18/2018
08:15 AM
Scott Ferguson
Scott Ferguson
News Analysis-Security Now
50%
50%

Shamoon Malware Re-Emerges With Attacks in Italy, Middle East

Over the last week, several reports emerged that the Shamoon malware, which was last seen in 2016, has re-emerged with attacks in Italy and the Middle East. This version includes a destructive data file wiper.

Over the last week, several reports have found that the Shamoon malware has re-emerged, including attacks against oil and gas companies in Italy and the Middle East, following a two-year absence.

Additionally, security researchers have found that this version of Shamoon includes a destructive data wiper that can delete files from infected systems before the malware fully removes all the data from the Master Boot Record.

The first attack appears to have targeted Saipem, an Italian oil company, which announced the incident on December 10. Since then, the company has continued to recover, finding about 300 PCs infected with the malware.

Later, researchers at Symantec issued a December 14 report that found additional Shamoon attacks that targeted organizations in Saudi Arabia and the United Arab Emirates.

(Source: iStock)
(Source: iStock)

In the case of the incident involving Saipem, researchers with Palo Alto Network's Unit42 found that the attack involved Disttrack malware -- another name for Shamoon -- and that the sample they examined contained similarities between this one and others that happened in 2016, which are sometimes called Shamoon 2.

It's through this examination that researchers found the new wiping capabilities.

"Unlike past Shamoon attacks, this particular Disttrack wiper would not overwrite files with an image. Instead it would overwrite the MBR [Master Boot Record], partitions, and files on the system with randomly generated data," according to the Unit42 analysis.

In this case, Disttrack acts as a dropper in order to infect a PC and install the data wiper onto the system. However, researchers also found that the malware also helps spread the attack throughout the network by using stolen usernames and passwords to log into other computers.

Researchers also noted that the malware sample contained a specific wipe date of "12/7/2017," which would appear to be a mistake by the group. However, it can still be effective: "This older date is still effective as the Disttrack dropper will install and run the wiper module as long as the system date is after the wipe date," according to the report.

In its analysis, Symantec researchers found that the group behind the attack usually gathers these credentials during a reconnaissance phase before the main attack. This list is then copied first to a file called OCLC.exe and then sent to another tool by the name or Spreader.exe. This sequence then copies all the malware to as many computers as possible.

Symantec has its own name for this part of the attack called the Filerase Trojan.

During the recent attack, Symantec noted that between the malware's ability to spread through the network, combined with the wipe capabilities, this particular attack is difficult to recover from once it starts.

"While a computer infected by Shamoon could be unusable, files on the hard disk may be forensically recoverable. However, if the files are first wiped by the Filerase malware, recovery becomes impossible," according to the company's analysis.

In the case of this most recent attack, Symantec noted that one company targeted by Shamoon had also been a victim of another piece of malware called Stonedrill, which is used by an Advanced Persistent Threat group (APT) called Elfin or APT33. It's possible the two are related but researchers could not draw a direct link as of yet.

From a historical perspective, researchers first noted Shamoon in 2012, when it attacked the network of Saudi Aramco -- the largest oil producer in Saudi Arabia -- infecting about 30,000 machines and stopping work at the company for some time.

Related posts:

— Scott Ferguson is the managing editor of Light Reading and the editor of Security Now. Follow him on Twitter @sferguson_LR.

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Enterprises are Attacking the Cybersecurity Problem
Concerns over supply chain vulnerabilities and attack visibility drove some significant changes in enterprise cybersecurity strategies over the past year. Dark Reading's 2021 Strategic Security Survey showed that many organizations are staying the course regarding the use of a mix of attack prevention and threat detection technologies and practices for dealing with cyber threats.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-33988
PUBLISHED: 2021-10-19
Cross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute Javascript by Inserting code in the request form.
CVE-2020-12141
PUBLISHED: 2021-10-19
An out-of-bounds read in the SNMP stack in Contiki-NG 4.4 and earlier allows an attacker to cause a denial of service and potentially disclose information via crafted SNMP packets to snmp_ber_decode_string_len_buffer in os/net/app-layer/snmp/snmp-ber.c.
CVE-2021-29912
PUBLISHED: 2021-10-19
IBM Security Risk Manager on CP4S 1.7.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 207828.
CVE-2021-38911
PUBLISHED: 2021-10-19
IBM Security Risk Manager on CP4S 1.7.0.0 stores user credentials in plain clear text which can be read by a an authenticatedl privileged user. IBM X-Force ID: 209940.
CVE-2021-3746
PUBLISHED: 2021-10-19
A flaw was found in the libtpms code that may cause access beyond the boundary of internal buffers. The vulnerability is triggered by specially-crafted TPM2 command packets that then trigger the issue when the state of the TPM2's volatile state is written. The highest threat from this vulnerability ...