Maritime Computer Emergency Response Team ADMIRAL dataset ADMIRAL dataset

Publicly disclosed information for this event

Index Number:
A virus is discovered on oil terminals.
Day Month Year Country Activity Incident Type
XX April 2012 Iran, Islamic Republic of Offshore Virus/Ransomware


A cyberattack on a primary oil terminal resulted in data being wiped from hard drives. While both "virus" and "worm" were terms used to describe the attack, the impact was significant, affecting multiple oil facilities. The main Kharg Island oil terminal, crucial for the nation's crude exports, was disconnected from the Internet to mitigate the attack's spread.

According to sources, despite this, oil production and exports remained undisturbed, even if several oil-linked institution websites went down, it is unclear whether this was due to the attack or a preventive measure to isolate them and prevent further infection or intrusion.



Claimed/Reported Threat Actor




Main impact



Recommendations to Offshore to reduce Virus/Ransomware risks:

  • Map, understand, patch and secure your exposed assets on the Internet.
  • Implement email filtering systems to detect and block phishing emails.
  • Train your organisation, personnel regularly against these threats.
  • Install efficient Endpoint Detection and Response (EDR) tools.
  • Work with your CSIRT organization to better understand the Tactics, Techniques and Procedures used by threat actors.
  • Monitor your IT and OT systems to quickly detect potential pre-ransomware activity.
  • Implement an efficient offline backup policy.
  • Encrypt all sensitive data to avoid further data leaks.
Previous Next
Disclaimer: the data are provided as is. France Cyber Maritime and the M-CERT take no responsibility for the soundness, quality, precision, nor the eventual attribution made by the referenced URLs. We give a lot of respect and support to the victims of attacks.
Files generated on Monday, 11th December 2023.
ADMIRAL is licensed under the Creative Commons CC-BY-NC license. Copyright © France Cyber Maritime 2023.