Sign up for our daily briefing

Make your busy days simpler with Axios AM/PM. Catch up on what's new and why it matters in just 5 minutes.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Stay on top of the latest market trends

Subscribe to Axios Markets for the latest market trends and economic insights. Sign up for free.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Sports news worthy of your time

Binge on the stats and stories that drive the sports world with Axios Sports. Sign up for free.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Tech news worthy of your time

Get our smart take on technology from the Valley and D.C. with Axios Login. Sign up for free.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Get the inside stories

Get an insider's guide to the new White House with Axios Sneak Peek. Sign up for free.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Catch up on coronavirus stories and special reports, curated by Mike Allen everyday

Catch up on coronavirus stories and special reports, curated by Mike Allen everyday

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Denver news?

Get a daily digest of the most important stories affecting your hometown with Axios Denver

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Des Moines news?

Get a daily digest of the most important stories affecting your hometown with Axios Des Moines

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Twin Cities news?

Get a daily digest of the most important stories affecting your hometown with Axios Twin Cities

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Tampa Bay news?

Get a daily digest of the most important stories affecting your hometown with Axios Tampa Bay

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Charlotte news?

Get a daily digest of the most important stories affecting your hometown with Axios Charlotte

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Investers stand in front of the Saudi Aramco logo in 2016. Photo: Fayez Nureldine / AFP via Getty Images.

Shamoon, the rarely seen but destructive malware that was used to wipe Saudi Aramco's servers in 2012, may be back in play, according to Chronicle, Alphabet's cybersecurity arm.

Why it matters: There are only three known times Shamoon variants have been used in the wild (and one of those instances is in dispute), with the Saudi incident the most famous. If the rare malware is back, it's an ominous sign.

Chronicle discovered a file containing Shamoon uploaded to its VirusTotal database. VirusTotal runs free scans on files using major antivirus scanners. The antivirus companies, in return, get access to valuable samples of malware that get uploaded.

  • The new Shamoon was set to detonate on Dec. 7, 2017, at 11:51 pm, but only uploaded yesterday.
  • Chronicle notes that attackers may have set the attack date to the past — perhaps by changing 2018 to 2017 — in order to start an attack immediately.
  • Another possibility, said Brandon Levene, head of applied intelligence at Chronicle, is that the malware was compiled in the past as part of preparations for a later attack.

The intrigue: "This variant is very strange," noted Levene.

  • All other Shamoon samples traveled through a network using pre-programmed credentials.
  • This sample has no pre-programmed credentials — it's limited to the computer it's first installed on.
  • Levene also said the command and control infrastructure — the internet address list allowing the malware to communicate with the hackers — was also blank.
  • "It's odd that those components aren't there," said Levene. "The attackers may have a different connection to the host network and thought manually installing Shamoon would make more sense."

Other differences include the way the malware goes about deleting files.

  • Shamoon in the past has replaced all files with images that had political significance. The new attacks irreversibly encrypt the files.

The file containing Shamoon was uploaded to VirusTotal from Italy.

  • Chronicle noted in a statement: "While Chronicle cannot directly link the new Shamoon variant to an active attack, the timing of the malware files comes close to news of an attack on an Italian energy corporation with assets in the Middle East."

Shamoon famously wipes the hard drives of networked computers after sending the attacker a list of the filenames that will be deleted. But in this latest variant of Shamoon, the lack of access to command and control servers means that function no longer works.

Go deeper

Cuomo: "No way I resign" after sexual harassment accusations

Cuomo at a Feb. 24 press conference. Photo: Seth Wenig/pool/AFP via Getty Images

New York Gov. Andrew Cuomo (D) was defiant on Sunday, stating again that he would not resign even as more former aides have come forward with allegations of sexual harassment and inappropriate behavior.

The big picture: Cuomo has denied all sexual harassment allegations against him and said that he "never inappropriately touched anybody." He acknowledged in a statement that "some of the things I have said have been misinterpreted as an unwanted flirtation." Some of the calls for Cuomo to resign have come from within the Democratic party.

N.Y. Times faces culture clashes as business booms

Illustration: Sarah Grillo/Axios

New York Times columnist David Brooks' resignation from a paid gig at a think tank on Saturday is the latest in a flurry of scandals that America's biggest and most successful newspaper company has endured in the past year.

Driving the news: Brooks resigned from the Aspen Institute following a BuzzFeed News investigation that uncovered conflicts of interest between his reporting and money he accepted from corporate donors for a project called "Weave" that he worked on at the nonprofit.

America rebalances its post-Trump news diet

Illustration: Annelise Capossela/Axios

Nearly halfway through President Biden's first 100 days, data shows that Americans are learning to wean themselves off of news — and especially politics.

Why it matters: The departure of former President Trump's once-ubiquitous presence in the news cycle has reoriented the country's attention.