{"id":2345,"date":"2019-01-16T14:11:46","date_gmt":"2019-01-16T14:11:46","guid":{"rendered":"https:\/\/www.varutra.com\/blog\/?p=1767"},"modified":"2022-12-02T15:38:07","modified_gmt":"2022-12-02T10:08:07","slug":"security-advisory-saipem-cyber-attack-by-shamoon-malware","status":"publish","type":"post","link":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-saipem-cyber-attack-by-shamoon-malware\/","title":{"rendered":"Security Advisory &#8211; Saipem Cyber Attack by Shamoon Malware"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/varutra-1a3b6.kxcdn.com\/wp-content\/uploads\/2019\/01\/saipem-1024x683.png\"  class=\"sh-overlay-item sh-table-cell ls-is-cached lazyloaded\" data-rel=\"lightcase\" title=\"saipem - Varutra Consulting\"><br \/>\n<strong>Saipem Cyber Attack by Shamoon Malware<\/strong><\/p>\n<h3 style=\"text-align: left\"><a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2019\/01\/Shamoon-malware-1.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1803 size-full alignleft\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2019\/01\/Shamoon-malware-1.jpg\" alt=\"Saipem Cyber Attack by Shamoon Malware\" width=\"728\" height=\"380\" \/><\/a><\/h3>\n<h3 style=\"text-align: left\"><strong>1. Introduction<\/strong><\/h3>\n<p style=\"text-align: left\">Saipem identified cyber-attack on Monday i.e. on 10th December 2018 that had primarily affected its servers in the Middle East. The cyber-attack hit servers based in the Middle East, India, and Aberdeen and in a limited way Italy through a variant of Shamoon malware. Shamoon malware is also known as Disttrack. The attack crippled between 300 and 400 servers and up to 100 personal computers out of a total of about 4,000 Saipem machines. The company does not know who was responsible for the attack.<\/p>\n<p>&nbsp;<\/p>\n<h3 style=\"text-align: left\"><strong>2. Shamoon Malware<\/strong><\/h3>\n<p style=\"text-align: left\">Shamoon is a disk-wiping malware it disables computers by overwriting master boot record making it impossible for devices to start up. Once overwritten the data is not recoverable. Shamoon is designed to destroy computer hard drives. It attempts to access default shared folders like Admin$ shares to spread among the network. It uses remote registry to disable UAC (User Access Control) and enable shares &amp; to spread through the network. Shamoon relies on the remote registry system to disable User Account Control on the remote target, allowing the malware to install itself in the %WinDir%\\ system32 directory and create a Scheduled Task without alerting the user.<\/p>\n<p style=\"text-align: left\">Distribution Method: Via Trojan installation and password stealing.<\/p>\n<p>&nbsp;<\/p>\n<h3 style=\"text-align: left\"><strong>3. Prevention and Remediation With SIEM<\/strong><\/h3>\n<p style=\"text-align: left\">In order to prevent future infection and lateral movement of the malware across the enterprise, the following actions can be taken in addition to implementing the SIEM rules. Because these mitigations have implications across the enterprise network, it is important to assess the impact of making these changes and ensure appropriate policies and procedures to implement and support these changes are evaluated.<\/p>\n<p style=\"text-align: left\">The Shamoon malware does not rely on exploiting application or operating system vulnerabilities to be successful. Instead, it uses hardcoded Windows Active Directory credentials and weak domain security configurations to infect and spread across the enterprise. Prevention of this type of attack requires hardening of the security policy on the network. Following are examples of security measures that should be implemented and how each prevents attacks such as Shamoon:<\/p>\n<p style=\"text-align: left\">Note: If the malware is successful in wiping the affected systems, analysts can remediate this malware from a system or network only by restoring from backup.<\/p>\n<p style=\"text-align: left\">Below are the indicator of compromise:<\/p>\n<p style=\"text-align: left\"><a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2019\/01\/IoC.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1769 size-full\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2019\/01\/IoC.png\" alt=\"indicator of compromise\" width=\"915\" height=\"477\" \/><\/a><\/p>\n<h3 style=\"text-align: left\"><\/h3>\n<h3><strong>4. Varutra Recommendation<\/strong><\/h3>\n<p style=\"text-align: left\">1. Maintain the strong passwords policy.<br \/>\n2. Disable credential caching for all desktop devices.<br \/>\n3. Restricting account privileges.<br \/>\n4. Where possible, disable RDP on critical devices.<br \/>\n5. Ensure all network operating systems, web browsers, and other related network hardware and<br \/>\nsoftware are updated with all current patches and fixes.<br \/>\n6. Restrict users permissions to install and run unwanted software applications.<br \/>\n7. Any unused applications or functions should be removed or disabled.<br \/>\n8. Consider the deployment of software restriction policy set to only allow the execution of<br \/>\napproved software (application whitelisting).<br \/>\n9. Consider the use of two-factor authentication methods for accessing privileged root level<br \/>\naccounts or systems.<br \/>\n10. Ensure the latest account credential protection is enabled on all Windows systems by verifying<br \/>\nthat enterprise systems are kept updated with the latest Windows Update software.<br \/>\n11. Educate users to not to open and download suspicious files and to inform ITIM department if<br \/>\nthey receive any spam or phishing email.<br \/>\n12. Keeping up to date antivirus signature set on the machines and enable the disabled antivirus<br \/>\ncomponents.<\/p>\n<h3 style=\"text-align: left\"><strong>5. Reference<\/strong><\/h3>\n<ol style=\"text-align: left\">\n<li><a href=\"https:\/\/www.reuters.com\/article\/us-cyber-shamoon\/saipem-says-shamoon-variant-crippledhundreds-of-computers-idUSKBN1OB2FA\">https:\/\/www.reuters.com\/article\/us-cyber-shamoon\/saipem-says-shamoon-variant-crippledhundreds-of-computers-idUSKBN1OB2FA<\/a><\/li>\n<li><a href=\"https:\/\/www.symantec.com\/connect\/blogs\/shamoon-back-dead-and-destructive-ever\">https:\/\/www.symantec.com\/connect\/blogs\/shamoon-back-dead-and-destructive-ever<\/a><\/li>\n<\/ol>\n<p><em>Author,<\/em><br \/>\n<strong><em>Umang Waghmare<\/em><\/strong><\/p>\n<p><em>SOC Team<\/em><\/p>\n<p><em>Varutra Consulting Pvt. Ltd.<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Saipem Cyber Attack by Shamoon Malware 1. Introduction Saipem identified cyber-attack on Monday i.e. on 10th December 2018 that had primarily affected its servers in&#8230;<\/p>\n","protected":false},"author":3,"featured_media":3221,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[276,269,270,266,280],"tags":[169,170,171,127,172,173],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 4.9.9 - aioseo.com -->\n\t<meta name=\"description\" content=\"Saipem cyber attack that affected its servers based in the Middle East, India, and Aberdeen and in a limited way Italy through a variant of Shamoon malware.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"kalpadmin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-saipem-cyber-attack-by-shamoon-malware\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 4.9.9\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Varutra Consulting\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Saipem Cyber Attack by Shamoon Malware - Security Advisory\" \/>\n\t\t<meta property=\"og:description\" content=\"Saipem cyber attack that affected its servers based in the Middle East, India, and Aberdeen and in a limited way Italy through a variant of Shamoon malware.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-saipem-cyber-attack-by-shamoon-malware\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2019\/01\/saipem.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2019\/01\/saipem.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1125\" \/>\n\t\t<meta property=\"og:image:height\" content=\"750\" \/>\n\t\t<meta property=\"article:section\" content=\"Cyber Attack\" \/>\n\t\t<meta property=\"article:tag\" content=\"cyber attack\" \/>\n\t\t<meta property=\"article:tag\" content=\"saipem\" \/>\n\t\t<meta property=\"article:tag\" content=\"saipem cyber attack\" \/>\n\t\t<meta property=\"article:tag\" content=\"security advisory\" \/>\n\t\t<meta property=\"article:tag\" content=\"shamoon\" \/>\n\t\t<meta property=\"article:tag\" content=\"shamoon malware\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-01-16T14:11:46+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-12-02T10:08:07+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Saipem Cyber Attack by Shamoon Malware - Security Advisory\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Saipem cyber attack that affected its servers based in the Middle East, India, and Aberdeen and in a limited way Italy through a variant of Shamoon malware.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2019\/01\/saipem.png\" \/>\n\t\t<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t\t<meta name=\"twitter:data1\" content=\"kalpadmin\" \/>\n\t\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-saipem-cyber-attack-by-shamoon-malware\\\/#article\",\"name\":\"Saipem Cyber Attack by Shamoon Malware - Security Advisory\",\"headline\":\"Security Advisory &#8211; Saipem Cyber Attack by Shamoon Malware\",\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/saipem.png\",\"width\":1125,\"height\":750,\"caption\":\"saipem\"},\"datePublished\":\"2019-01-16T14:11:46+05:30\",\"dateModified\":\"2022-12-02T15:38:07+05:30\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-saipem-cyber-attack-by-shamoon-malware\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-saipem-cyber-attack-by-shamoon-malware\\\/#webpage\"},\"articleSection\":\"Cyber Attack, Data Breaches, Data Leakage, Security Advisory, Viruses &amp; Malware, Cyber Attack, SaiPem, SaiPem Cyber Attack, Security Advisory, Shamoon, Shamoon Malware\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-saipem-cyber-attack-by-shamoon-malware\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/security-advisory\\\/#listItem\",\"name\":\"Security Advisory\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/security-advisory\\\/#listItem\",\"position\":2,\"name\":\"Security Advisory\",\"item\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/security-advisory\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-saipem-cyber-attack-by-shamoon-malware\\\/#listItem\",\"name\":\"Security Advisory &#8211; Saipem Cyber Attack by Shamoon Malware\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-saipem-cyber-attack-by-shamoon-malware\\\/#listItem\",\"position\":3,\"name\":\"Security Advisory &#8211; Saipem Cyber Attack by Shamoon Malware\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/security-advisory\\\/#listItem\",\"name\":\"Security Advisory\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\",\"name\":\"Varutra\",\"description\":\"Secure your digital world with our Cybersecurity services.\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/Varutra-Found-e1612984024606.jpg\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-saipem-cyber-attack-by-shamoon-malware\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-saipem-cyber-attack-by-shamoon-malware\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/\",\"name\":\"kalpadmin\",\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d69b4bf504d3e2e3c6ad0c424e16bcb2?s=96&d=mm&r=g\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-saipem-cyber-attack-by-shamoon-malware\\\/#webpage\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-saipem-cyber-attack-by-shamoon-malware\\\/\",\"name\":\"Saipem Cyber Attack by Shamoon Malware - Security Advisory\",\"description\":\"Saipem cyber attack that affected its servers based in the Middle East, India, and Aberdeen and in a limited way Italy through a variant of Shamoon malware.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-saipem-cyber-attack-by-shamoon-malware\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/saipem.png\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-saipem-cyber-attack-by-shamoon-malware\\\/#mainImage\",\"width\":1125,\"height\":750,\"caption\":\"saipem\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/security-advisory-saipem-cyber-attack-by-shamoon-malware\\\/#mainImage\"},\"datePublished\":\"2019-01-16T14:11:46+05:30\",\"dateModified\":\"2022-12-02T15:38:07+05:30\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"name\":\"Varutra Consulting\",\"description\":\"Secure your digital world with our Cybersecurity services.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Saipem Cyber Attack by Shamoon Malware - Security Advisory<\/title>\n\n","aioseo_head_json":{"title":"Saipem Cyber Attack by Shamoon Malware - Security Advisory","description":"Saipem cyber attack that affected its servers based in the Middle East, India, and Aberdeen and in a limited way Italy through a variant of Shamoon malware.","canonical_url":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-saipem-cyber-attack-by-shamoon-malware\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-saipem-cyber-attack-by-shamoon-malware\/#article","name":"Saipem Cyber Attack by Shamoon Malware - Security Advisory","headline":"Security Advisory &#8211; Saipem Cyber Attack by Shamoon Malware","author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author"},"publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2019\/01\/saipem.png","width":1125,"height":750,"caption":"saipem"},"datePublished":"2019-01-16T14:11:46+05:30","dateModified":"2022-12-02T15:38:07+05:30","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-saipem-cyber-attack-by-shamoon-malware\/#webpage"},"isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-saipem-cyber-attack-by-shamoon-malware\/#webpage"},"articleSection":"Cyber Attack, Data Breaches, Data Leakage, Security Advisory, Viruses &amp; Malware, Cyber Attack, SaiPem, SaiPem Cyber Attack, Security Advisory, Shamoon, Shamoon Malware"},{"@type":"BreadcrumbList","@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-saipem-cyber-attack-by-shamoon-malware\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3#listItem","position":1,"name":"Home","item":"https:\/\/www.varutra.com\/varutravrt3","nextItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/security-advisory\/#listItem","name":"Security Advisory"}},{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/security-advisory\/#listItem","position":2,"name":"Security Advisory","item":"https:\/\/www.varutra.com\/varutravrt3\/category\/security-advisory\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-saipem-cyber-attack-by-shamoon-malware\/#listItem","name":"Security Advisory &#8211; Saipem Cyber Attack by Shamoon Malware"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-saipem-cyber-attack-by-shamoon-malware\/#listItem","position":3,"name":"Security Advisory &#8211; Saipem Cyber Attack by Shamoon Malware","previousItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/security-advisory\/#listItem","name":"Security Advisory"}}]},{"@type":"Organization","@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization","name":"Varutra","description":"Secure your digital world with our Cybersecurity services.","url":"https:\/\/www.varutra.com\/varutravrt3\/","logo":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/11\/Varutra-Found-e1612984024606.jpg","@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-saipem-cyber-attack-by-shamoon-malware\/#organizationLogo"},"image":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-saipem-cyber-attack-by-shamoon-malware\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author","url":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/","name":"kalpadmin","image":{"@type":"ImageObject","url":"https:\/\/secure.gravatar.com\/avatar\/d69b4bf504d3e2e3c6ad0c424e16bcb2?s=96&d=mm&r=g"}},{"@type":"WebPage","@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-saipem-cyber-attack-by-shamoon-malware\/#webpage","url":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-saipem-cyber-attack-by-shamoon-malware\/","name":"Saipem Cyber Attack by Shamoon Malware - Security Advisory","description":"Saipem cyber attack that affected its servers based in the Middle East, India, and Aberdeen and in a limited way Italy through a variant of Shamoon malware.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#website"},"breadcrumb":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-saipem-cyber-attack-by-shamoon-malware\/#breadcrumblist"},"author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author"},"creator":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2019\/01\/saipem.png","@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-saipem-cyber-attack-by-shamoon-malware\/#mainImage","width":1125,"height":750,"caption":"saipem"},"primaryImageOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-saipem-cyber-attack-by-shamoon-malware\/#mainImage"},"datePublished":"2019-01-16T14:11:46+05:30","dateModified":"2022-12-02T15:38:07+05:30"},{"@type":"WebSite","@id":"https:\/\/www.varutra.com\/varutravrt3\/#website","url":"https:\/\/www.varutra.com\/varutravrt3\/","name":"Varutra Consulting","description":"Secure your digital world with our Cybersecurity services.","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"}}]},"og:locale":"en_US","og:site_name":"Varutra Consulting","og:type":"article","og:title":"Saipem Cyber Attack by Shamoon Malware - Security Advisory","og:description":"Saipem cyber attack that affected its servers based in the Middle East, India, and Aberdeen and in a limited way Italy through a variant of Shamoon malware.","og:url":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-saipem-cyber-attack-by-shamoon-malware\/","og:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2019\/01\/saipem.png","og:image:secure_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2019\/01\/saipem.png","og:image:width":"1125","og:image:height":"750","article:section":"Cyber Attack","article:tag":["cyber attack","saipem","saipem cyber attack","security advisory","shamoon","shamoon malware"],"article:published_time":"2019-01-16T14:11:46+00:00","article:modified_time":"2022-12-02T10:08:07+00:00","twitter:card":"summary_large_image","twitter:title":"Saipem Cyber Attack by Shamoon Malware - Security Advisory","twitter:description":"Saipem cyber attack that affected its servers based in the Middle East, India, and Aberdeen and in a limited way Italy through a variant of Shamoon malware.","twitter:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2019\/01\/saipem.png","twitter:label1":"Written by","twitter:data1":"kalpadmin","twitter:label2":"Est. reading time","twitter:data2":"3 minutes"},"aioseo_meta_data":{"post_id":"2345","title":"Saipem Cyber Attack by Shamoon Malware - Security Advisory","description":"Saipem cyber attack that affected its servers based in the Middle East, India, and Aberdeen and in a limited way Italy through a variant of Shamoon malware.&nbsp;","keywords":[],"keyphrases":{"focus":{"keyphrase":"Saipem Cyber Attack","score":80,"analysis":{"keyphraseInTitle":{"title":"Focus keyphrase in SEO title","description":"Focus keyphrase found in SEO title.","score":9,"maxScore":9,"error":0},"keyphraseInDescription":{"title":"Focus keyphrase in meta description","description":"Focus keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Focus keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":3},"keyphraseInURL":{"title":"Focus keyphrase in URL","description":"Focus keyphrase used in the URL.","score":5,"maxScore":5,"error":0},"keyphraseInIntroduction":{"title":"Focus keyphrase in introduction","description":"Your Focus keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.","score":3,"maxScore":9,"error":1},"keyphraseInSubHeadings":{"title":"Focus keyphrase in Subheadings","description":"Use your focus keyphrase more in your H2 and H3 subheadings.","score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"title":"Focus keyphrase in image alt attributes","description":"Focus keyphrase found in image alt attribute(s).","score":9,"maxScore":9,"error":0}}},"additional":[{"keyphrase":"Cyber Attack","score":83,"analysis":{"keyphraseInDescription":{"title":"Keyphrase in meta description","description":"Keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":2},"keyphraseInIntroduction":{"title":"Keyphrase in introduction","description":"Your Keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.","score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"title":"Keyphrase in image alt attributes","description":"Keyphrase found in image alt attribute(s).","score":9,"maxScore":9,"error":0}}},{"keyphrase":"Saipem","score":100,"analysis":{"keyphraseInDescription":{"title":"Keyphrase in meta description","description":"Keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":1},"keyphraseInIntroduction":{"title":"Keyphrase in introduction","description":"Your Keyphrase appears in the first paragraph. Well done!","score":9,"maxScore":9,"error":0},"keyphraseInImageAlt":{"title":"Keyphrase in image alt attributes","description":"Keyphrase found in image alt attribute(s).","score":9,"maxScore":9,"error":0}}},{"keyphrase":"Shamoon Malware","score":100,"analysis":{"keyphraseInDescription":{"title":"Keyphrase in meta description","description":"Keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":2},"keyphraseInIntroduction":{"title":"Keyphrase in introduction","description":"Your Keyphrase appears in the first paragraph. Well done!","score":9,"maxScore":9,"error":0},"keyphraseInImageAlt":{"title":"Keyphrase in image alt attributes","description":"Keyphrase found in image alt attribute(s).","score":9,"maxScore":9,"error":0}}},{"keyphrase":"Shamoon","score":100,"analysis":{"keyphraseInDescription":{"title":"Keyphrase in meta description","description":"Keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":1},"keyphraseInIntroduction":{"title":"Keyphrase in introduction","description":"Your Keyphrase appears in the first paragraph. Well done!","score":9,"maxScore":9,"error":0},"keyphraseInImageAlt":{"title":"Keyphrase in image alt attributes","description":"Keyphrase found in image alt attribute(s).","score":9,"maxScore":9,"error":0}}},{"keyphrase":"Malware","score":100,"analysis":{"keyphraseInDescription":{"title":"Keyphrase in meta description","description":"Keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":1},"keyphraseInIntroduction":{"title":"Keyphrase in introduction","description":"Your Keyphrase appears in the first paragraph. Well done!","score":9,"maxScore":9,"error":0},"keyphraseInImageAlt":{"title":"Keyphrase in image alt attributes","description":"Keyphrase found in image alt attribute(s).","score":9,"maxScore":9,"error":0}}}]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"featured","og_image_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2019\/01\/saipem.png","og_image_width":"1125","og_image_height":"750","og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"Cyber Attack","og_article_tags":[],"twitter_use_og":true,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":"{\"article\":{\"articleType\":\"BlogPosting\"},\"course\":{\"name\":\"\",\"description\":\"\",\"provider\":\"\"},\"faq\":{\"pages\":[]},\"product\":{\"reviews\":[]},\"recipe\":{\"ingredients\":[],\"instructions\":[],\"keywords\":[]},\"software\":{\"reviews\":[],\"operatingSystems\":[]},\"webPage\":{\"webPageType\":\"WebPage\"}}","pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"limit_modified_date":false,"reviewed_by":null,"open_ai":null,"created":"2021-10-27 15:16:26","updated":"2026-05-24 09:18:18","ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":"2026-05-22 12:50:21"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\/category\/security-advisory\/\" title=\"Security Advisory\">Security Advisory<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tSecurity Advisory \u2013 Saipem Cyber Attack by Shamoon Malware\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.varutra.com\/varutravrt3"},{"label":"Security Advisory","link":"https:\/\/www.varutra.com\/varutravrt3\/category\/security-advisory\/"},{"label":"Security Advisory &#8211; Saipem Cyber Attack by Shamoon Malware","link":"https:\/\/www.varutra.com\/varutravrt3\/security-advisory-saipem-cyber-attack-by-shamoon-malware\/"}],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/2345"}],"collection":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/comments?post=2345"}],"version-history":[{"count":6,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/2345\/revisions"}],"predecessor-version":[{"id":20351,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/2345\/revisions\/20351"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media\/3221"}],"wp:attachment":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media?parent=2345"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/categories?post=2345"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/tags?post=2345"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}