Reuters
A version of Shamoon, the destructive computer virus that four years ago crippled tens of thousands of computers at Middle Eastern energy companies, was used two weeks ago to attack computers in Saudi Arabia, according to U.S. security firms.
CrowdStrike, Palo Alto Networks Inc and Symantec Corp. warned of the new attacks on Wednesday. They did not name any victims of the new version of Shamoon, which cripples computers by wiping their master boot records that they use to start up. They also did not say how much damage had been caused or identify the hackers.
Saudi Arabia confirmed on Thursday that hackers had launched a virus attack on computers in government bodies and installations including the kingdom’s transport sector in mid-November, heightening concern about security in the world’s largest oil exporter.
The attack originated outside
the country and was one of “several ongoing cyberattacks targeting government authoritiesâ€, the National Cyber Security Center, an arm of
the Ministry of Interior, told state news agency SPA.
The statement did not give further details of the identity of the attacker or the damage that had been done, beyond saying the virus aimed to disrupt servers and plant malicious software in computer systems.
The reappearance of Shamoon is significant as there have only been a handful of other high-profile attacks involving disk-wiping malware, including ones in 2014 on Sheldon Adelson’s Las Vegas Sands Corp. and Sony Corp’s Hollywood studio. Governments and businesses pay close attention to such cases because it can be time-consuming and extremely expensive to restore infected systems.
The Saudi business week ends on Thursday, so it appears to have been timed to begin after staff left for the weekend to reduce the chance of
discovery and allow maximum damage. “The malware had potentially the entire weekend to spread,†Palo Alto researcher Robert Falcone said in a blog post.