Sign up for our daily briefing

Make your busy days simpler with Axios AM/PM. Catch up on what's new and why it matters in just 5 minutes.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Catch up on the day's biggest business stories

Subscribe to Axios Closer for insights into the day’s business news and trends and why they matter

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Stay on top of the latest market trends

Subscribe to Axios Markets for the latest market trends and economic insights. Sign up for free.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Sports news worthy of your time

Binge on the stats and stories that drive the sports world with Axios Sports. Sign up for free.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Tech news worthy of your time

Get our smart take on technology from the Valley and D.C. with Axios Login. Sign up for free.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Get the inside stories

Get an insider's guide to the new White House with Axios Sneak Peek. Sign up for free.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Axios on your phone

Get breaking news and scoops on the go with the Axios app.

Download for free.

Catch up on coronavirus stories and special reports, curated by Mike Allen everyday

Catch up on coronavirus stories and special reports, curated by Mike Allen everyday

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Denver news?

Get a daily digest of the most important stories affecting your hometown with Axios Denver

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Des Moines news?

Get a daily digest of the most important stories affecting your hometown with Axios Des Moines

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Twin Cities news?

Get a daily digest of the most important stories affecting your hometown with Axios Twin Cities

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Tampa Bay news?

Get a daily digest of the most important stories affecting your hometown with Axios Tampa Bay

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Charlotte news?

Get a daily digest of the most important stories affecting your hometown with Axios Charlotte

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Sign up for Axios NW Arkansas

Stay up-to-date on the most important and interesting stories affecting NW Arkansas, authored by local reporters

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Investers stand in front of the Saudi Aramco logo in 2016. Photo: Fayez Nureldine / AFP via Getty Images.

Shamoon, the rarely seen but destructive malware that was used to wipe Saudi Aramco's servers in 2012, may be back in play, according to Chronicle, Alphabet's cybersecurity arm.

Why it matters: There are only three known times Shamoon variants have been used in the wild (and one of those instances is in dispute), with the Saudi incident the most famous. If the rare malware is back, it's an ominous sign.

Chronicle discovered a file containing Shamoon uploaded to its VirusTotal database. VirusTotal runs free scans on files using major antivirus scanners. The antivirus companies, in return, get access to valuable samples of malware that get uploaded.

  • The new Shamoon was set to detonate on Dec. 7, 2017, at 11:51 pm, but only uploaded yesterday.
  • Chronicle notes that attackers may have set the attack date to the past — perhaps by changing 2018 to 2017 — in order to start an attack immediately.
  • Another possibility, said Brandon Levene, head of applied intelligence at Chronicle, is that the malware was compiled in the past as part of preparations for a later attack.

The intrigue: "This variant is very strange," noted Levene.

  • All other Shamoon samples traveled through a network using pre-programmed credentials.
  • This sample has no pre-programmed credentials — it's limited to the computer it's first installed on.
  • Levene also said the command and control infrastructure — the internet address list allowing the malware to communicate with the hackers — was also blank.
  • "It's odd that those components aren't there," said Levene. "The attackers may have a different connection to the host network and thought manually installing Shamoon would make more sense."

Other differences include the way the malware goes about deleting files.

  • Shamoon in the past has replaced all files with images that had political significance. The new attacks irreversibly encrypt the files.

The file containing Shamoon was uploaded to VirusTotal from Italy.

  • Chronicle noted in a statement: "While Chronicle cannot directly link the new Shamoon variant to an active attack, the timing of the malware files comes close to news of an attack on an Italian energy corporation with assets in the Middle East."

Shamoon famously wipes the hard drives of networked computers after sending the attacker a list of the filenames that will be deleted. But in this latest variant of Shamoon, the lack of access to command and control servers means that function no longer works.

Go deeper

Dan Primack, author of Pro Rata
22 mins ago - Economy & Business

The mobile gaming gold rush

Illustration: Aïda Amer/Axios

Electronic Arts this morning announced that it will pay $1.4 billion to buy Playdemic, a mobile gaming studio whose titles include "Golf Clash," from Warner Bros.

Why it matters: This comes just months after EA paid $2.1 billion to buy Glu Mobile. It also resolves talk that not all of WB Games would get included in the Discovery merger.

Felix Salmon, author of Capital
2 hours ago - Economy & Business

Warren Buffett resigns from Gates Foundation board

Buffett and Bill Gates in 2015. Photo: Dimitrios Kambouris/Getty Images

The Bill and Melinda Gates Foundation — the second-largest philanthropy in the world — is now governed by just two trustees, after Warren Buffett announced on Wednesday that he had resigned his position there.

Why it matters: The two remaining trustees, Bill Gates and Melinda French Gates, are going through a divorce.

Updated 2 hours ago - World

U.K. denies Russia fired warning shots at destroyer in Black Sea

The HMS Defender in the port of Odessa on Ukraine's Black Sea coast on June 18. Photo: Konstantin Sazonchik\TASS via Getty Images

Russia's defense ministry claimed Wednesday that a Russian warship and fighter jet fired "warning" shots at the British Royal Navy’s HMS Defender destroyer for encroaching on waters near Crimea in the Black Sea.

The latest: The U.K.'s ministry of defense disputed that any warning shots were fired, saying in a statement, "We believe the Russians were undertaking a gunnery exercise in the Black Sea and provided the maritime community with prior-warning of their activity."