What Was Shamoon? The Attack That Bought the World's Hard Drives
They went back to typewriters.
Not as a figure of speech. Saudi Aramco, a company then moving something in the order of ten million barrels of oil a day, spent months running its purchasing, its contracts, its shipping paperwork and its payroll on typewriters, fax machines and interoffice mail, because it had disconnected itself from the internet and had no working computers to do it on.
Shamoon is filed as an attack on an oil company. It is worth being precise about what it actually took down, because it was not oil. Production never stopped. What stopped was every desk in the building.
What was Shamoon?
Shamoon — also catalogued as Disttrack — was a wiper: malware whose purpose is destruction rather than theft, extortion or espionage. It ran at Saudi Aramco on 15 August 2012, and at Qatar's RasGas days later.
It took roughly 30,000 workstations off the network at Aramco — about three quarters of the company's PCs.
The name comes from the malware itself: a folder path left in the binary contained the string shamoon. It was not a name anyone chose for marketing. It is the sort of artifact that ends up in a compiled program when nobody expected anyone to look.
The date was chosen
15 August 2012 fell during Ramadan, close to Lailat al Qadr, one of the holiest nights of the Islamic year. Most of Aramco's staff were on leave.
That is why the wiping ran as far as it did. There was nobody at a desk to notice screens going dark, nobody to pull a cable, and by the time anyone with authority understood what was happening, tens of thousands of machines had already had their boot sectors overwritten.
Every serious destructive operation since has picked its date the same way. It is the least technical and most reliable component of the entire attack.
It used a legitimate, signed driver
This is the part worth knowing, and it is the reason the attack worked on hardened Windows machines.
Overwriting a disk directly — past the filesystem, into the master boot record and raw sectors — is not something a normal user-mode program can do. Windows will not permit it. You need a kernel driver, and since 64-bit Windows, drivers must be signed.
So Shamoon brought one. It carried a copy of RawDisk, a genuine commercial driver from a company called EldoS, correctly signed and properly licensed, sold to legitimate developers who need raw disk access for backup and forensic tools.
Shamoon dropped it, loaded it, and used it exactly as documented, for exactly what it was built to do. Nothing was exploited. No signature was forged. No vulnerability was involved at any point in getting write access to the disk.
It is the clean example of a technique the industry now calls bring-your-own-vulnerable-driver, except the driver was not even vulnerable. It was just useful, and signed, and available. The same driver reappeared in later wipers, including in the 2014 attack on Sony Pictures.
What it wrote over the files
Shamoon overwrote the master boot record, the partition tables and the contents of files, and it did not overwrite them with zeroes or random data.
It used a JPEG of a burning American flag.
There is no technical reason to do that. Zeroes destroy data just as thoroughly and considerably faster. Writing an image means the payload has to carry it, which makes the binary larger and easier to spot. It was a message, aimed at whoever eventually pulled the drives and looked.
When Shamoon returned in November 2016, against Saudi government ministries and industry, the image had been changed to a photograph of Alan Kurdi, the three-year-old Syrian boy who drowned in the Mediterranean in 2015. A third wave followed in 2018.
Whoever ran it kept the code and updated the picture.
Who did it, and who says so
Responsibility was claimed on Pastebin by a group calling itself the Cutting Sword of Justice, framing the attack as a response to Saudi policy in the region. The claim included the start time and matched the observed activity.
US officials, speaking anonymously at the time and more openly later, attributed the attack to Iran. That attribution has never been formally proven in public, and it is worth holding it at the distance the evidence supports — the strongest public arguments are timing, target selection and the reuse of the toolkit in later campaigns against Saudi targets, not forensic proof.
The context usually offered is that Shamoon came roughly two years after Stuxnet was found at Natanz. Whether that is causation or sequence is genuinely unsettled.
Not one barrel
The line that ran in most coverage was that a cyberattack had hit the world's largest oil producer, with the implication that supply was at risk.
Aramco's industrial control systems were on a separate network and were not affected. Oil production continued throughout. Not one barrel of output was lost to Shamoon.
What was lost was the entire corporate side of a company that moves that oil. Purchasing. Contracts. Shipping documentation. Payroll. Email. The systems that decide which tanker loads what, and who gets paid for it.
Domestically, Aramco kept fuel moving by giving it away — there was no functioning way to bill for it, so tankers were sent out and the accounting was deferred.
This is the distinction the incident actually teaches, and it is one most write-ups skip: the operational technology was fine, and the company was still nearly stopped, because a modern industrial business is not the plant. It is the paperwork about the plant.
They bought the world's hard drives
The recovery is the part almost nobody knows, and it is the best fact in the whole incident.
Thirty thousand machines needed thirty thousand replacement drives, immediately, and the global supply chain was still recovering from the 2011 Thai floods that had knocked out a large share of world hard drive manufacturing.
So Aramco sent staff, with company money, directly to hard drive factories in Southeast Asia, and bought output straight off the production line — ahead of everyone else's existing orders. Reporting at the time put the purchase at around 50,000 drives, and credited it with moving the global price of hard drives.
Aramco could do that because Aramco has more money than the hard drive industry. It is not a control any other organisation can implement, and that is rather the point: the company's stated recovery capability was, in the end, the ability to outbid the planet.
It took around five months to get back to normal operations.
What is still true
Shamoon established the wiper as a category, and the category has only grown — through Dark Seoul, through the Sony Pictures attack in 2014, through NotPetya in 2017, through the wipers deployed against Ukraine from 2022 onward.
The defensive lesson is not about the malware, which was not especially sophisticated. It is that recovery capacity is a real, physical, finite thing. Aramco's plan for thirty thousand destroyed endpoints was to buy thirty thousand new ones, and it worked because of who they are.
Most organisations have no such plan. They have backups of data, which is not the same as having somewhere to restore it to.
Further reading
- Symantec Security Response — The Shamoon Attacks, August 2012, and the 2016 and 2018 follow-ups on Shamoon 2 and 3.
- Kaspersky Lab — Shamoon the Wiper, August 2012. The early analysis, including the EldoS RawDisk component.
- Jose Pagliery, CNN — The inside story of the biggest hack in history, August 2015. The typewriters, the free fuel and the hard drive buying.
- Bloomberg Businessweek — coverage of the Aramco recovery and its effect on drive pricing.
- US Department of Homeland Security — ICS-CERT alerts on Shamoon and Disttrack, 2012 and 2016.
EXHIBIT 0020 — SHAMOON
We put it on a shirt. Not a burning flag and not a server rack — a wooden pallet stacked with shrink-wrapped bricks of brand-new hard drives, drawn as an engraving, with a shipping tag hanging off the corner reading 50,000.
The callouts are the incident: 30,000 WORKSTATIONS WIPED, BOUGHT DIRECT, AT PREMIUM, SIGNED RAWDISK DRIVER. Underneath, the line that corrects the record: NOT ONE BARREL. THIRTY THOUSAND DESKTOPS.
Most people see a pallet of drives. Anyone who has ever costed a disaster recovery plan sees what that pallet cost, and how fast it had to arrive.
That's the whole idea.