Threat actor · all actors
OpPetrol / Cutting Sword of JusticeHACK-OP-SAUDI-ARAMCO hacktivist
aka Cutting Sword of Justice, OpPetrol
Last updated:
0attributed CVEs
0ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
—years active
About this actor
The hacktivist persona that claimed responsibility for the August 2012 Shamoon wiper attack against Saudi Aramco, which destroyed data on roughly 35,000 workstations. US intelligence subsequently attributed the operation to Iran-aligned operators, with the hacktivist branding serving as cover. A reference case for destructive hacktivism.
How we know this
- Data origin
- Curated overlay Hacktivist entry synthesised from public reporting — not a MITRE-tracked intrusion set.
- Techniques
- No ATT&CK techniques mapped.
- Named victims
- 1 extracted from reporting.
Thin data: No ATT&CK techniques are mapped yet — the behavioural profile is empty. Only one named victim is on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
No techniques attributed.
Co-occurring actors
None.