Donate Us

Help us keep this free site alive with a small contribution from you. Select an amount below.

Monday, October 15, 2012

From PC Magazine:
Researchers have uncovered a new virus with ties to the Flame and Gauss malware. According to Kaspersky Lab, its latest discovery has "many similarities to Flame," prompting researchers to dub it miniFlame.

"MiniFlame is in fact based on the Flame platform but is implemented as an independent module. It can operate either independently, without the main modules of Flame in the system, or as a component controlled by Flame," Kaspersky said in a blog post.

MiniFlame was uncovered in July 2012, but has apparently been in development for several years. Kaspersky believes there are dozens of different miniFlame modifications; at this point, the firm has identified six.

While Flame and Gauss hit a large number of targets, miniFlame appears to be focused on a few systems in Western Asia. "This indicates that [miniFlame] is a tool used for highly targeted attacks, and has probably been used only against very specific targets that have the greatest significance and posing the greatest interest to the attackers," Kaspersky said.

MiniFlame also does not appear to be targeting a specific region. Flame was mostly focused in Iran and Sudan, while Gauss had a major presence in Lebanon. Different miniFlame variants, however, have clustered in regions like Lebanon and Palestine as well as Iran, Kuwait, and Qatar.

"If Flame and Gauss were massive spy operations, infecting thousands of users, miniFlame/SPE is a high precision, surgical attack tool," Kaspersky said.

MiniFlame, however, can be used in conjunction with its larger counterparts, like Gauss. "As many readers will remember, it has been assumed that Flame and Gauss were parallel projects that did not have any modules or C&C servers in common," Kaspersky said. "The discovery of miniFlame, which works with both these espionage projects, proves that we were right when we concluded that they had come out of the same 'cyber-weapon factory."

Kaspersky uncovered Flame in late May, and said at the time that it "might be the most sophisticated cyber weapon yet unleashed." Flame can sniff network traffic, take screenshots, record audio conversations, intercept a keyboard, and more. All of this data is then available via Flame's command-and-control servers.

Gauss, meanwhile, was uncovered in August and is a cyber threat targeting users in the Middle East that is intended to steal personal details, like banking information. Gauss includes a module - known as Godel - that has an encrypted payload, which Kaspersky found difficult to crack. Ultimately, it asked the security community for assistance.
Russian company Kaspersky, which has effectively become Iran's cyber-defense contractor, linked Flame and Stuxnet previously.

It is widely assumed that these suites of computer malware were designed by Israel and the US.

--
Posted By Elder of Ziyon to Elder of Ziyon at 10/15/2012 01:15:00 PM

0 comments:

Post a Comment

EoZTV Podcast

Powered by Blogger.

follow me

search eoz

Recent posts from other blogs

subscribe via email

comments

Contact

translate

E-Book

source materials

reference sites

multimedia

source materials for Jewish learning

great places to give money

media watch

humor

.

Source materials

Sample Text

EoZ's Most Popular Posts Ever

follow me

Followers


pages

Random Posts

Pages - Menu

Elder of Ziyon - حـكـيـم صـهـيـون

Donate!

Tweets

Compliments

Monthly subscription:
Subscription options

One time donation:

Interesting Blogs

Categories

Best posts of 2016

Blog Archive

compliments

Algemeiner: "Fiercely intelligent and erudite"

Omri: "Elder is one of the best established and most respected members of the jblogosphere..."
Atheist Jew:"Elder of Ziyon probably had the greatest impression on me..."
Soccer Dad: "He undertakes the important task of making sure that his readers learn from history."
AbbaGav: "A truly exceptional blog..."
Judeopundit: "[A] venerable blog-pioneer and beloved patriarchal figure...his blog is indispensable."
Oleh Musings: "The most comprehensive Zionist blog I have seen."
Carl in Jerusalem: "...probably the most under-recognized blog in the JBlogsphere as far as I am concerned."
Aussie Dave: "King of the auto-translation."
The Israel Situation:The Elder manages to write so many great, investigative posts that I am often looking to him for important news on the PalArab (his term for Palestinian Arab) side of things."
Tikun Olam: "Either you are carelessly ignorant or a willful liar and distorter of the truth. Either way, it makes you one mean SOB."
Mondoweiss commenter: "For virulent pro-Zionism (and plain straightforward lies of course) there is nothing much to beat it."
Didi Remez: "Leading wingnut"