logo

Revived Shamoon Virus Causing Disruptions in Saudi Oil Sector

ID: ce171130-fd1e-5658-b9a5-c3d6c77d5476

STIX ID: report--ce171130-fd1e-5658-b9a5-c3d6c77d5476

Feed Name: Security Ledger

Threat Score
85/100

Date Published: 2017-01-24

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

Symantec reported a campaign in the Middle East using the Shamoon destructive wiper alongside an Ismdoor trojan attributed to a state-linked actor called “Greenbug.” Multiple public and private organizations across energy, aviation, government and other sectors were impacted via phishing emails; the operation reportedly combined data theft and disk-wiping destructive activity and is suspected to be linked to Iran.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.