logo

Destructive Shamoon Malware Attacks Italian Oil Services Firm

ID: 3bad63a5-fefb-5334-b4d6-04ea4576b343

STIX ID: report--3bad63a5-fefb-5334-b4d6-04ea4576b343

Feed Name: Security Ledger

Threat Score
78/100

Date Published: 2018-12-13

Date Updated: 2026-04-26

Author: Elizabeth Montalbano

...
...

The Shamoon data‑wiping malware resurfaced in December, impacting contractor Saipem and destroying files on about 10% of its PCs across regions including the Middle East, India, Aberdeen and Italy. The report links this variant to earlier Shamoon campaigns targeting energy firms (notably Saudi Aramco), notes possible ties to Iranian‑linked actors (Greenbug), and highlights new VirusTotal sample uploads and a hard‑coded trigger date that may signal additional or future attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.