manchesterwired
Technology
Flame: Massive cyber-attack discovered, researchers say
Published: 28th May 2012 14:17:05
A complex targeted cyber-attack that collected private data from countries such as Israel and Iran has been uncovered, researchers have said.
Russian security firm Kaspersky Labs told the BBC they believed the malware, known as Flame, had been operating since August 2010.
The company said it believed the attack was state-sponsored, but could not be sure of its exact origins.
They described Flame as "one of the most complex threats ever discovered".
Research into the attack was carried out in conjunction with the UN's International Telecommunication Union.
In the past, targeted malware - such as Stuxnet - has targeted nuclear infrastructure in Iran.
Others like Duqu have sought to infiltrate networks in order to steal data.
This new threat appears not to cause physical damage, but to collect huge amounts of sensitive information, said Kaspersky's chief malware expert Vitaly Kamluk.
"Once a system is infected, Flame begins a complex set of operations, including sniffing the network traffic, taking screenshots, recording audio conversations, intercepting the keyboard, and so on," he said.
More than 600 specific targets were hit, Mr Kamluk said, ranging from individuals, businesses, academic institutions and government systems.
Iran's National Computer Emergency Response Team posted a security alert stating that it believed Flame was responsible for "recent incidents of mass data loss" in the country.
Mr Kamluk said the size and sophistication of Flame suggested it was not the work of independent cybercriminals, and more likely to be government-backed.
He explained: "Currently there are three known classes of players who develop malware and spyware: hacktivists, cybercriminals and nation states.
"Flame is not designed to steal money from bank accounts. It is also different from rather simple hack tools and malware used by the hacktivists. So by excluding cybercriminals and hacktivists, we come to conclusion that it most likely belongs to the third group."
Among the countries affected by the attack are Iran, Israel, Sudan, Syria, Lebanon, Saudi Arabia and Egypt.
"The geography of the targets and also the complexity of the threat leaves no doubt about it being a nation-state that sponsored the research that went into it," Mr Kamluk said.
The malware is capable of recording audio via a microphone, before compressing it and sending it back to the attacker.
It is also able to take screenshots of on-screen activity, automatically detecting when "interesting" programs - such as email or instant messaging - were open.
Kaspersky's first recorded instance of Flame is in August 2010, although it said it is highly likely to have been operating earlier.
Prof Alan Woodward, from the Department of Computing at the University of Surrey said the attack is very significant.
"This is basically an industrial vacuum cleaner for sensitive information," he told the BBC.
He explained that unlike Stuxnet, which was designed with one specific task in mind, Flame was much more sophisticated.
"Whereas Stuxnet just had one purpose in life, Flame is a toolkit, so they can go after just about everything they can get their hands on."
Once the initial Flame malware has infected a machine, additional modules can be added to perform specific tasks - almost in the same manner as adding apps to a smartphone.
Harvard Citation
BBC News, 2012. Flame: Massive cyber-attack discovered, researchers say. [Online] (Updated 28 May 2012)Available at: http://www.manchesterwired.co.uk/news.php/1431353-Flame-Massive-cyber-attack-discovered-researchers-say [Accessed 19th June 2013]
Latest News
-
At 07:44:02 in Other
Breast cancer scientists say less invasive surgery possible
Some breast cancer sufferers could be treated with radiotherapy instead of more invasive surgery after a Europe-wide study.... -
At 06:12:16 in Other
East Ham named identity fraud hotspot
People living in London's East Ham are more likely to be the victims of identity fraud than anyone else in the UK, figures suggest. ... -
At 01:52:36 in Headlines
Iraq damages cases: Supreme Court judges to rule
Supreme Court judges will rule later on whether relatives of soldiers killed in Iraq can sue the government for damages under the Human Righ... -
At 20:47:00 in Other
Bolton park assault 'was an accident'
Police investigating how a 12-year-old girl got a serious head injury in a Bolton park have concluded it happened by accident. ... -
At 20:02:36 in Other
Murder arrest after woman's body found in Greater Manchester
A man has been arrested on suspicion of murder after a woman was found dead at a house in Greater Manchester.... -
At 19:00:51 in Other
Girl, 13, raped on way to school in Wigan
A 13-year-old girl was raped on her way to school in Greater Manchester.... -
At 18:39:05 in Other
Woman raped by group of men at party in Manchester
A woman was raped by a number of men during a house party in a "disgusting" attack, police have said.... -
At 13:44:40 in Other
Moors Murderer Ian Brady banned from carrying pens
Ian Brady is banned from carrying pens in case he uses them as a weapon after a confrontation at his secure mental hospital, a tribunal has ... -
At 10:50:26 in Other
Culture minister: No threat to northern science museums
Museums in three northern cities which faced uncertain futures are "safe" from closure, the culture minister has said.... -
At 03:49:06 in Other
HS2 rail plans: Think tank raises doubts over value
Demand for the HS2 high-speed rail project has "likely been overestimated", a think tank has said....
News In Other Categories
-
Bristol Academy extends reach overseas with first foreign students
With the doors to its brand new £1million training centre officially open, one of the UK's leading apprentice training providers, Bristol ba... -
Stafford Hospital nurses said dead woman was sleeping
Two nurses who failed to give basic life support to an 81-year-old woman at Stafford Hospital, recording that she was asleep when she was ac... -
Ballet dancer David Wall dies aged 67
Ballet dancer David Wall, who became the youngest male principal in the history of the Royal Ballet at the age of 21, has died of cancer.... -
Ballet dancer David Wall dies aged 67
Ballet dancer David Wall, who became the youngest male principal in the history of the Royal Ballet at the age of 21, has died of cancer.... -
East Ham named identity fraud hotspot
People living in London's East Ham are more likely to be the victims of identity fraud than anyone else in the UK, figures suggest. ... -
Ballet dancer David Wall dies aged 67
Ballet dancer David Wall, who became the youngest male principal in the history of the Royal Ballet at the age of 21, has died of cancer....



