logo

Charming_Kitten__2017__Report_Shamoon_StoneDrill_final.pdf

ID: d05f0b2a-902a-497d-b7ac-e93d7b9a0361

STIX ID: report--d05f0b2a-902a-497d-b7ac-e93d7b9a0361

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2017-03-06

Last Modified Date: 2017-03-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky Lab documents multiple waves of the destructive Shamoon 2.0 wiper targeting Saudi organizations and the discovery of a related but distinct wiper named StoneDrill (with links to the NewsBeef actor). The report provides technical analysis of dropper, C2, wiper and driver usage, anti-emulation and injection techniques, a list of MD5s and C2 domains, and notes Shamoon 2.0 contains a dormant ransomware capability while StoneDrill focuses on memory injection and sandbox evasion.