Kaspersky discovers miniFlame cyberespionage malware directly linked to Flame and Gauss
MiniFlame serves as a backdoor that gives attackers direct access to infected computers
IDG News Service - Security researchers from Kaspersky Lab have identified another piece of malware targeting the Middle East that is likely part of the interrelated cyberespionage efforts behind Stuxnet, Duqu, Flame and Gauss.
The malware was dubbed miniFlame because its code suggests that it was built on the same platform as the highly sophisticated Flame threat discovered in May. However, the functionality of miniFlame -- called SPE by its authors -- is different.
"Flame and Gauss are mostly about data and information stealing," Roel Schouwenberg, a senior researcher at Kaspersky Lab, said Monday via email. "MiniFlame serves as a backdoor which gives the operator direct access to an infected machine. So yes, the functionality and intent is different."
"If Flame and Gauss were massive spy operations, infecting thousands of users, SPE/miniFlame is a high precision espionage tool," the Kaspersky researchers said in a blog post that details their findings.
MiniFlame can function independently on a computer, but also as a Flame or, more surprisingly, as a Gauss module. Kaspersky researchers had previously established a relationship between Flame and Gauss based on code similarities, but miniFlame's ability to function as a module for both threats represents the most conclusive proof that they are related.
"We can assume this malware was part of the Flame and Gauss operations which took place in multiple waves," the Kaspersky researchers said. "First wave: infect as many potentially interesting victims as possible. Secondly, data is collected from the victims, allowing the attackers to profile them and find the most interesting targets. Finally, for these 'select' targets, a specialized spy tool such as SPE/miniFlame is deployed to conduct surveillance/monitoring."
The method used to infect computers with miniFlame has not been established yet, but the researchers believe that the malware might be downloaded and installed by Flame or Gauss. This is because most of the miniFlame-infected computers have also been infected with Flame or Gauss in the past.
"It is also possible that SPE is part of some sort of main Flame dropper (as yet undiscovered), or is in fact the unknown encrypted payload which was distributed by Gauss on USB disks," the Kaspersky researchers said.
"The Flame self-destruction plug-in does not delete any SPE files," Schouwenberg said. "It has to be removed separately. We need to view miniFlame as a separate operation to the others, so it makes sense. We can assume the authors hoped SPE would go unnoticed after Flame's (and Gauss') discovery."
MiniFlame is capable of downloading files from a command and control (C&C) server, uploading a file from the machine to the server, loading a specified DLL file, creating a process with given parameters or taking screen shots of the active window if it belongs to a program from a list.
- Chinese hackers master the art of lying in wait
- Spy court OK'd all U.S. wiretap requests it received in 2012
- Groups denounce FBI plan to require Internet backdoors for wiretaps
- South Korea cyberattacks hold lessons for U.S.
- U.S. military networks not prepared for cyberthreats, report warns
- Return of CISPA: Cybersecurity boon or privacy threat?
- New report says cyberspying group linked to China's army
- Obama executive order redefines critical infrastructure
- Obama cybersecurity order lacks bite, security experts say
- Obama seen likely to urge Congress to pass cybersecurity laws in State of the Union address
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Case Study: Hospital Turns to Email Archiving Solution to Ensure Regulatory Compliances Read this case study to learn how a cloud-based email archiving solution enabled the hospital to meet government mandates and helps avoid thousands...
- Case Study: In-the-Cloud Email Service Replaces Three Point Products Read this case study for more information on a comprehensive in-the-cloud email service to help replace three point products.
- What does it take to deliver Security, Privacy and Trust at Mimecast? This whitepaper explains the process and controls that Mimecast put in place to deliver a secure, private and trusted SaaS platform for your...
- Your Data under Siege: Defeating the Enemy of Complexity Even if you have adequate antivirus protection, are there still holes in your IT security armor? Is lack of bandwidth to manage the...
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts
