Safe Mode: On
Global cyber war: New Flame-linked malware detected

A new cyber espionage program linked to the notorious Flame and Gauss malware has been detected by Russia's Kaspersky Lab. The anti-virus giant’s chief warns that global cyber warfare is in “full swing” and will probably escalate in 2013.

The virus, dubbed miniFlame, and also known as SPE, has already infected computers in Iran, Lebanon, France, the United States and Lithuania. It was discovered in July 2012 and is described as “a small and highly flexible malicious program designed to steal data and control infected systems during targeted cyber espionage operations,” Kaspersky Lab said in a statement posted on its website.

The malware was originally identified as an appendage of Flame – the program used for targeted cyber espionage in the Middle East and acknowledged to be part of joint US-Israeli efforts to undermine Iran’s nuclear program.

But later, Kaspersky Lab analysts discovered that miniFlame is an “interoperable tool that could be used as an independent malicious program, or concurrently as a plug-in for both the Flame and Gauss malware.”

The analysis also showed new evidence of cooperation between the creators of Flame and Gauss, as both viruses can use miniFlame for their operations.

“MiniFlame’s ability to be used as a plug-in by either Flame or Gauss clearly connects the collaboration between the development teams of both Flame and Gauss. Since the connection between Flame and Stuxnet/Duqu has already been revealed, it can be concluded that all these advanced threats come from the same 'cyber warfare' factory,” Kaspersky Lab said.

High-precision attack tool

So far just 50 to 60 cases of infection have been detected worldwide, according to Kaspersky Lab. But unlike Flame and Gauss, miniFlame in meant for installation on machines already infected by those viruses.

“MiniFlame is a high-precision attack tool. Most likely it is a targeted cyber weapon used in what can be defined as the second wave of a cyber attack,” Kaspersky's Chief Security Expert Alexander Gostev explained.

“First, Flame or Gauss are used to infect as many victims as possible to collect large quantities of information. After data is collected and reviewed, a potentially interesting victim is defined and identified, and miniFlame is installed in order to conduct more in-depth surveillance and cyber-espionage.”

The newly-discovered malware can also take screenshots of an infected computer while it is
running a specific program or application in such as a web browser, Microsoft Office program, Adobe Reader, instant messenger service or FTP client.

Kaspersky Lab believes miniFlame's developers have probably created dozens of different modifications of the program. "At this time, we have only found six of these, dated 2010-2011," the firm said.

‘Cyber warfare in full swing’

Meanwhile, Kaspersky Lab’s co-founder and CEO Eugene Kaspersky warned that global cyber warfare tactics are becoming more sophisticated while also becoming more threatening. He urged governments to work together to fight cyber warfare and cyber-terrorism, Xinhua news agency reports.

Speaking at an International Telecommunication Union Telecom World conference in Dubai, the anti-virus tycoon said, "cyber warfare is in full swing and we expect it to escalate in 2013."

"The latest malicious virus attack on the world's largest oil and gas company, Saudi Aramco, last
August shows how dependent we are today on the Internet and information technology in general, and how vulnerable we are," Kaspersky said.

He stopped short of blaming any particular player behind the massive cyber attacks across the Middle East, pointing out that "our job is not to identity hackers or cyber-terrorists. Our firm is like an X-ray machine, meaning we can scan and identify a problem, but we cannot say who or what is behind it."

Iran, who confirmed that it suffered an attack by Flame malware that caused severe data loss, blames the United States and Israel for unleashing the cyber attacks.

http://rt.com/news/mini-flame-malware-kaspersky-519/


Added: Oct-16-2012 Occurred On: Oct-16-2012
By: focusv5
In:
World News
Tags: New, Flame, Linked, Malware, Detected, miniFlame, Kaspersky, Iran, Lebanon, France, United States, Lithuania
Location: Earth, Texas, United States (load item map)
Marked as: approved
Views: 1240 | Comments: 12 | Votes: 1 | Favorites: 0 | Shared: 0 | Updates: 0 | Times used in channels: 2
You need to be registered in order to add comments! Register HERE
Sort by: Newest first | Oldest first | Highest score first
Liveleak opposes racial slurs - if you do spot comments that fall into this category, please report them for us to review.
  • It was fun to watch them finally figure out it's Israel and the US... But that was months and months ago.

    Thought they might be more careful in the future...
    ...But no.

    Posted Oct-16-2012 By 

    (1)

  • Sounds like a 'Cheap Trick" . . .

    Posted Oct-16-2012 By 

    (1)

  • Everyone always blames the US , Israel, sometimes Russia of things like this , few really mention China. If there's one that is more ambitious than the one on top , it's the one just under.

    Posted Oct-16-2012 By 

    (1)

  • china is stealing more intellectual and classified government property on a daily basis than anyone in history and using it to further their citizens economic welfare. wake up you tools, you wont have a clue until you write that first mortgage check to the great red dragon bank.


    this world is entirely too dependent on the interwebz, you could absolutely demolish the entire worlds economy with a simple power outage. might be time to go back to using paper.

    Posted Oct-16-2012 By 

    (1)

  • Greater likelihood many of the newer virus and malware programs are brought to us by our own as an excuse to write an executive order and take control of the internet. Recent press reports state "growing attacks" against American infrastructure. So really, how much critical infrastructure is on the net? Maybe that's the problem? But I doubt serious and critical infrastructure is simply out there like Amazon.c0m. If so, change it.
    I have no doubt there's Chinese attacks, however, I'm al More..

    Posted Oct-16-2012 By 

    (1)

  • Bollocks

    Posted Oct-16-2012 By 

    (0)

  • Flame is dead(I know its sad), get over it. "epIc_timers" will never come again ;)

    Posted Oct-16-2012 By 

    (0)

  • so a cyber weapon used against Iran now has a new form that is being used against the US etc...interesting

    Posted Oct-16-2012 By 

    (0)

  • I heard Israel and its lapdog are preparing a massive cyber-attack on electronic financial transaction systems, a cyber 9/11 that be blamed on Anonymous or Iran to crack down on Internet and eventually rip everybody from thir bank savings.

    Posted Oct-16-2012 By 

    (0)

    • @JohnMcLane2008 Operation Square-Peg Round-Hole: assault Chinese data centers with missiles and cyber attacks. No debt if there was never any proof that it existed.

      Posted Oct-16-2012 By 

      (1)

  • too bad someone doesn't develop a virus against islam

    Posted Oct-16-2012 By 

    (0)