Shamoon, also known as Disttrack, was first spotted in a wave of attacks that targeted companies in Saudi Arabia in 2012. The principal capability of Shamoon is a feature that allows it to wipe data from hard drives of the infected systems. In the attack against Saudi Aramco Shamoon wipe data on over 30,000 computers and rewrite the hard drive MBR (Master Boot Record) with an image of a burning US flag. Now the threat is back, security experts from Palo Alto Networks and Symantec spotted it in an attack on a single Saudi company.”]

