Shamoon malware virus swipes and wipes PCs

Shamoon
New malware threat renders PCs useless

A new, swipe-and-wipe malware virus is under investigation by security companies the world over as they try to determine its source and how to keep it from infecting any more PCs.

Called "Shamoon," the virus works by infiltrating a system connected to the internet then spreads to other PCs within that network, including ones without a web connection.

So far, at least one organization has been attacked - Saudi Arabia's national oil company.

"[Shamoon] is a new threat that is being used in specific targeted attacks against at least one organization in the energy sector," a Symantec security system's blog post stated.

"It is a destructive malware that corrupts files on a compromised computer and overwrites the MBR in an effort to render the computer unusable."

What is Shamoon?

Shamoon, also known as Disttrack, nabs data from PC folders like "Documents and Settings" and "System32/Config," stealing information as any malware virus would do.

However, what's different about Shamoon is that it's able to overwrite the master boot record (MBR) of the machines it infiltrates, crippling them completely.

In the case of the Saudi oil company, stolen data was replaced with JPEG images, preventing any future file recovery.

Analysts think Shamoon is a copycat virus, taking cues from the "Wiper" virus that swept through Iran in April, though believe there is no connection between the two.

Shamoon is likely "the work of script kiddies inspired by the story."

Three-pronged attack

Symantec broke down the virus' components into three main parts: dropper, wiper and reporter.

Through each step, Shamoon gathers, destroys and retrieves information for the attacker.

One analyst explained the virus' wiping component as an attempt by the attackers to cover their tracks.

Some think the virus' name may be taken from the Shamoon College of Engineering in Israel.

Another theory has it named after one of the virus' authors - Shamoon means "Simon" in Arabic.

Via Symantec, ComputerWorld, SecureList, BBC and ZDNet

TOPICS
Michelle Fitzsimmons

Michelle was previously a news editor at TechRadar, leading consumer tech news and reviews. Michelle is now a Content Strategist at Facebook.  A versatile, highly effective content writer and skilled editor with a keen eye for detail, Michelle is a collaborative problem solver and covered everything from smartwatches and microprocessors to VR and self-driving cars.

Latest in Windows PCs
Dell XPS 13 and Alienware M16 laptops on purple background with big savings text overlay
Dell's site-wide Tech Days sale is live: see the 6 best laptop and gaming laptop deals from just $299
Microsoft presenting Surface Laptop and Surface Pro devices.
Microsoft has pulled a miracle: its Surface Copilot PCs are now the most repairable in the market
asian woman using laptop at business table
Finally, some good Copilot news: Microsoft could be making 16GB RAM a standard for AI PCs
The Acer Predator Orion 3000 gaming PC on a blue and pink background with the text 'TechRadar Cyber Monday PC deals'.
Cyber Monday PC deals 2023 – the best extended deals still live
The Microsoft Outlook logo on a laptop screen
Two unloved Windows 11 apps are getting canned - but will their replacement be any better?
Business man holding a tablet
The PCs protecting workers on the move
Latest in News
An image of Pro-Ject's Flatten it closed and opened
Pro-Ject’s new vinyl flattener will fix any warped LPs you inadvertently buy on Record Store Day
EA Sports F1 25 promotional image featuring drivers Oscar Piastri, Carlos Sainz and Oliver Bearman.
F1 25 has been officially announced, with this year's entry marking a return for Braking Point and a 'significant overhaul' for My Team mode
Garmin clippd integration
Garmin's golf watches just got a big software integration upgrade to help you improve your game
Robert Downey Jr reveals himself as Doctor Doom to a delighted crowd at San Diego Comic-Con 2024
Marvel is currently revealing the full cast for Avengers: Doomsday, and I think it's going to be a long-winded announcement
Samsung QN90F on yellow background
Samsung announces US prices for its 2025 mini-LED TV lineup, and it’s good and bad news
Nintendo Switch Lite
Forget the Nintendo Switch 2, the original Switch is getting one last hurrah in a surprise Nintendo Direct tomorrow