Greenbug may answer the question of how Shamoon obtains the stolen credentials needed to carry out its disk-wiping attacks.
Symantec is currently investigating reports of yet another new attack in the Middle East involving the destructive disk-wiping malware used by the Shamoon group (W32.Disttrack, W32.Disttrack.B).