MiniFlame virus is Flame's smaller, more dangerous cousin

Advertisement
By Reuters | Updated: 16 October 2012 11:20 IST
The security company that has discovered some of the most sophisticated spying software unearthed to date says it found a related program, dubbed "miniFlame," which can carry out more precise attacks on targets in the Middle East.

While the original Flame virus swept in data from perhaps 5,000 computers, largely in Iran and Sudan, the new miniFlame struck only about 50 "high-value" machines, according to Kaspersky Lab research published on Monday. Iran had previously blamed Flame for causing data loss on computers in the country's main oil export terminal and Oil Ministry.

"Flame acts as a long sword for broad swipes while miniFlame acts as a scalpel for a focused surgical dissection," Roel Schouwenberg, a senior researcher at Moscow-based Kaspersky Lab, told Reuters.

Kaspersky theorized that miniFlame was distributed mainly by Flame and another recently discovered spyware program, Gauss, which was most prevalent in Lebanon and may have been aimed at tracking financial transactions.

Advertisement

Not much is known about miniFlame's victims, except that they were more geographically dispersed than those of Flame and Gauss. Infections were found in Lebanon and Iran most of all but also in the Palestinian Territories, Iran, Kuwait, and Qatar, according to Kaspersky.

Advertisement

Kaspersky and U.S. security software company Symantec Corp have said that some of the code in Flame also appeared in an early version of Stuxnet. Found in 2010 and aimed at Iran's nuclear enrichment program, Stuxnet is sometimes described as the first true cyber-weapon. Cyber experts widely believe Stuxnet is an American project.

Kaspersky and Symantec said in a joint research paper last month that Flame's control software remotely directed a number of smaller programs, and that the effects of only one of those programs was clear.

Advertisement

Symantec said at the time the overall project "fits the profile of military and intelligence operations," in part because encryption kept some operatives in the dark about what data they were taking from infected machines.

The many technological innovations in Flame included its hijacking of Microsoft Corp's Windows Update feature, which is critical for keeping the operating system current as new security problems come to light.

Advertisement

The new discovery concerns one of the smaller programs controlled by the Flame command software, referred to in the original code as SPE.

According to the Kaspersky analysis, it includes a "back door" allowing for remote control, data theft and the ability to take screen shots or images of the computer screen as the user engages with Microsoft Office, Adobe Systems Inc's Reader, web browsers, and other applications.

"MiniFlame is installed in order to conduct more in-depth surveillance and cyber-espionage," Kaspersky Chief Security Expert Alexander Gostev said.

Symantec said on Friday it had no new information on Flame or the related programs.

Kaspersky said that miniFlame worked with Flame and Gauss but could also operate independently of both, taking orders from a separate network of command computers. It said the new discovery makes a stronger case for the connection among all the programs, though it has not accused any party of authorship.

Kaspersky said it found six versions of miniFlame, the most recent created in September 2011. Some of the protocols it used dated to 2007, making it a long-running effort.

MiniFlame responded to a series of commands given Anglo first names by the program authors. "Elvis" created a process on an infected machine and "Barbara" took a screen shot. "Tiffany" directed the computer to a new command server.

In a speech on Thursday, U.S. Secretary of Defense Leon Panetta warned that the country could act pre-emptively against imminent cyber attacks that would cause "significant physical damage" or kill U.S. citizens. He said the Pentagon was rewriting its rules for engagement in cyberspace.

Though it has been ramping up its capabilities, the Pentagon has said little in public about what it can do.

Copyright Thomson Reuters 2012

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Stuxnet, Flame virus, Kaspersky, MiniFlame
Advertisement

Related Stories

Popular Mobile Brands
  1. NASA Confirms Third Interstellar Visitor 3I/ATLAS Is a Natural Comet
  2. Redmi Note 16 Pro+, Realme 16 Pro+ Tipped to Launch Soon
  3. Realme P4x 5G Price in India Leaked; Here's How Much It Might Cost
  4. Lava Play Max Could Launch in India Soon at This Price
  5. iQOO 15 Sale in India Begins Today: All You Need to Know
  6. Vivo X300 Ultra Launch Timeline, Battery Capcity Leaked
  7. Vivo V70 FE Tipped to Launch in India Soon With These Specifications
  8. Nothing Phone 3a Series Gets Nothing OS 4.0 Update With These Features
  9. Xiaomi 17 Ultra Tipped to Launch Soon With This Leica Camera Upgrade
  1. New GTA 6 Leak Allegedly Shows In-Development Footage From Game
  2. Gustakh Ishq OTT Release Reportedly Revealed Online: When and Where to Watch it Online?
  3. Nithari: Truth, Lies & Murder Now Streaming Online: Plot, Cast, Crew, Streaming Details, and More
  4. Seher Hone Ko Hai OTT Release: Cast, Plot, Trailer, Storyline, and Complete Drama Summary
  5. Vivo V70 FE India Launch Timeline Leaked; Said to Debut With Snapdragon Chipset
  6. Vivo X300 Ultra Launch Timeline Leaked; Tipped to Arrive With 7,000mAh Battery
  7. Nothing Phone 3a, Phone 3a Pro Get Nothing OS 4.0 Update With Android 16, AI Usage Dashboard and More
  8. Bitcoin Price Slips to $85,000 Zone After Liquidation Shock; Crypto Market Eyes US Fed Shift
  9. OnePlus Ace 6T Camera Details Revealed: Expected Specifications, Features
  10. Oakley Meta Glasses With Meta AI Integration Now Available for Purchase in India: Price, Availability
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.