Oil Exporters Attacked by Malware Similar to That Used to Attack Iran
August 17, 2012 12:30 PM
comment(s) - last by
Attack vector differs slightly from the "Wiper" the malware used to attack the Iranian oil industry
Using a malware package
with tools with names like "Wiper", U.S. and Israeli intelligence teams are suspected of a concerted
campaign designed to cripple
Iran's oil industry
, a key supplier of Chinese demand and lifeblood of the Middle Eastern giant's economy.
But now the U.S. energy sector finds itself under attack by a somewhat similar piece of malware dubbed Shamoon or Disttrack by researchers
) and Intel Corp. (
The malware is named for its resident directory -- C:\Shamoon\ArabianGulf\wiper\release\wiper.pdb -- which, of course, is likely to change as new variants pop up. Shamoon means "Simon" in Arabic. There's also
Shamoon College of Engineering
in Israel -- another possible local name connection.
The malware contains a string in its compilation directory "wiper", making it clear that the authors intended it as at least a homage to the Iran-targeting Wiper. But Kaspersky Lab says that unlike Stuxnet -- where the U.S.'s anti-Iranian code was decompiled and used by malicious hackers -- the new malware is likely only an imitation, not repackaging.
The code uses different file and service names than the original Wiper. It also attacks with different attack pattern, though the net goal is the same -- to destroy hard drive data on infected energy sector computers.
Kaspersky Labs' analysis team
, "It is more likely that this is a copycat, the work of script kiddies inspired by the story."
But if script kiddies wrote the malware, they must be some pretty good ones. The malware has advanced networked propagation code, and overwrites the hard drive with a JPEG image found on the internet, preventing data recovery. While not exactly rocket science, those little touches are the kinds of sophistication oft overlooked by novice hackers.
Shamoon may have struck Saudi Arabia's oil industry, though infections are limited.
[Image Source: CNBC]
The state-owned Saudi Arabian Oil Comp., the world's largest oil producer and privately held company,
announced this week
that it was struck by a malware attack. It was unclear, however, whether Shamoon or a similar variant was responsible for the attack on one of America's largest foreign oil suppliers.
What is clear, based on expert reports is that the extent of infections is small, with Symantec reporting
less than 50 systems
This article is over a month old, voting and posting comments is disabled
RE: Oh great
8/17/2012 6:36:56 PM
Still cheap compared to the past when you factor in the buying value of a $, not to mention even the worst cars use less fuel then a decade ago.
"If you can find a PS3 anywhere in North America that's been on shelves for more than five minutes, I'll give you 1,200 bucks for it." -- SCEA President Jack Tretton
Microsoft Tightens Security, Deals IT Folks Headaches in Flame Fight
July 12, 2012, 12:00 PM
Microsoft Aims to Harden Windows Update to Fight "Flame"
June 6, 2012, 2:24 PM
Iranian Oil Industry Hit with Cyber Attack
April 24, 2012, 10:31 AM
Google's First Asian Data Centers Now Operational
December 11, 2013, 8:50 AM
IBM to Offer Watson Supercomputer as Cloud Development Platform
November 14, 2013, 12:00 PM
Microsoft May Use Fuel Cells at Rack Level for Greener, Cheaper Data Centers
November 13, 2013, 3:14 PM
Study: Problems with Surgical Robots Going Unreported to the FDA
November 5, 2013, 2:36 PM
Lenovo CEO Shares Bonus with Workers for a Second Year
September 2, 2013, 11:16 AM
Hacking the Gibson: 24 YO Scored Root on Nation's Top Supercomputers
August 28, 2013, 7:14 PM
Most Popular Articles
China's Lunar Rover Enters Orbit, Prepares for Historic Sat. Landing
December 13, 2013, 5:00 PM
Ten Senators Sponsor Bill to Scrap Corn Ethanol Market Manipulation
December 13, 2013, 1:52 PM
China's Moon Rover Lands Safe and Sound, Starts Snapping Pics
December 16, 2013, 1:22 PM
Metro-Enabled Firefox Browser Expected to Land After Two Years of Work
December 12, 2013, 5:21 PM
Top Microsoft Graphics Genius Defects to Google
December 17, 2013, 4:27 PM
Latest Blog Posts
Justice Leaks Details of Next HTC One Two Flagship Phone
Dec 5, 2013, 4:04 PM
Global Cyber Espionage Concerns Reveal Growing Cyber Armies
Nov 29, 2013, 11:04 AM
Is The Period Becoming an Expression of Anger?
Nov 26, 2013, 2:02 PM
NSA and Congress -- You Will Never Kill the Constitution, It's an Idea
Nov 10, 2013, 2:00 PM
AT&T Explores $100B+ USD Deal to Acquire Vodafone's European Operations
Nov 4, 2013, 7:34 AM
More Blog Posts
Copyright 2013 DailyTech LLC. -
Terms, Conditions & Privacy Information