Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Don't Get Shamoon'd by VDI Malware – Take These Steps Now current page
Link copied

Don't Get Shamoon'd by VDI Malware – Take These Steps Now

Jan 11, 2017
Author:
Scott Carlson
Technical Fellow
Blog banner default
Don't Get Shamoon'd by VDI Malware – Take These Steps Now
Scott Carlson
Technical Fellow

Don't Get Shamoon'd by VDI Malware

Virtual Desktop Infrastructure (VDI) has regained prevalence in recent years as a cost-effective way to deliver application services to users within a company. VMWare first coined the term VDI as: the practice of hosting a desktop operating system within a virtual machine (VM) running on a centralized server.

In the past few days, researchers have discovered a new type of malware that is directly targeting the infrastructure underneath virtual desktop solutions. No longer content with just creating destruction within VM’s themselves, this seems like the next attack, and one that will be much harder to recover from if your company experiences an event which results in the full deletion of your entire infrastructure.

What’s the Risk?

If a company has converted fully to a VDI infrastructure, they might have gone so far as to have removed all of the physical desktops from within the user environment. If they had a full VDI outage that took days to recover from, the loss of productivity – and possible revenue – would be extreme.

What can Prevent Malware like Shamoon?

What sorts of actions can you take to prevent malware such as shamoon from impacting your underlying VDI infrastructure? The answer to this question is very similar to things that you would do to protect other types of server infrastructure within your critical data center, namely:

  • Control administrative accounts and change any default passwords
  • Place a multi-factor jump-host in front of any administrative portal that allows access to the foundational infrastructure
  • Protect access to the underlying operating system like it is one of your most critical assets with the highest availability. It should be on its own dedicated network segment with appropriate access controls at both the network, jump-host, and on the physical operating system
  • Remove administrative rights from any user who needs to log into the operating system and only allow those programs specifically from the VDI vendor to operate with privilege
  • Continue to run common antivirus and anti-malware solutions on your VDI infrastructure. Do not worry about performance implications of these programs anymore, but be sure to pay close attention to temporary storage folders

The last thing we want as security professionals is to impact an environment in such a way that it that causes full user outage or financial impact. Take these steps to stop these sorts of attacks.

BeyondTrust is developing a reference architecture for all of our products against Citrix just so that we can help you solve these problems. If you’d like to learn more, contact us today.

Latest Posts
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
Related
  • You only hear what you want to
    Oct 20, 2017 You only hear what you want to
    Blog
    1m
  • Windows 7 & Server 2008 & R2 End-of-Life (EOL): One Clock Winds Down, Another Starts Ticking
    Feb 4, 2020 Windows 7 & Server 2008 & R2 End-of-Life (EOL): One Clock Winds Down, Another Starts Ticking
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.