THA:
Showing posts with label Flame virus. Show all posts
Showing posts with label Flame virus. Show all posts

US, Israel made Flame virus to thwart Iran: report

Written By THA on Wednesday, 20 June 2012 | 14:24

The United States and Israel collaborated to create the Flame computer virus as part of an effort to slow Iran's suspected nuclear weapons drive, The Washington Post reported Tuesday.

The newspaper, citing "Western officials with knowledge of the effort," said the sophisticated malware was designed to spy on Iran's computer networks and send back intelligence used for an ongoing cyberwarfare campaign.

The Post said the US National Security Agency and CIA worked with Israel's military on the project.

A number of reports had linked Israel and the United States to Flame and another virus called Stuxnet which caused malfunctions in Iran's nuclear enrichment equipment.

US officials have not publicly discussed the matter except to say that they are focused on cyber efforts as part of defense and intelligence.

"This is about preparing the battlefield for another type of covert action," one former high-ranking US intelligence official told the Post.

The Russian security firm Kaspersky, first credited with discovering Flame, said last week the malware had strong links to Stuxnet.

Kaspersky said its research shows the two programs share certain portions of code, suggesting some ties between two separate groups of programmers.

The New York Times reported June 1 that President Barack Obama accelerated cyberattacks on Iran's nuclear program and expanded the assault even after the Stuxnet virus accidentally escaped in 2010.

The cyberattack, aimed at preventing Iran from developing nuclear weapons and keeping Israel from launching a preventive military strike, sowed widespread confusion in Iran's Natanz nuclear plant, the Times said. (WASHINGTON - Agence France-Presse)

Flame spy virus gets order to vanish: experts

Written By THA on Monday, 11 June 2012 | 17:40

US computer security researchers said Sunday that the Flame computer virus that smoldered undetected for years in Middle Eastern energy facilities has gotten orders to vanish, leaving no trace.

Anti-virus company Symantec said in a blog post that late last week, some Flame "command-and-control servers sent an updated command to several compromised computers." "This command was designed to completely remove (Flame) from the compromised computers." Flame malicious software (malware) appears to have been "in the wild" for two years or longer and prime targets so far have been energy facilities in the Middle East, especially in Iran.

The discovery of Flame immediately sparked speculation that it had been created by US and Israeli security services to steal information about Iran's controversial nuclear drive.

Kaspersky Lab, one of the world's biggest producers of anti-virus software, said the Flame virus was "about 20 times larger than Stuxnet," the worm which was discovered in June 2010 and used against the Iranian nuclear program.

High concentrations of computers compromised by Flame were also found in Lebanon, the West Bank and Hungary. Additional infections have been reported in Austria, Russia, Hong Kong and the United Arab Emirates.

Compromised computers included many being used from home connections, according to security researchers who were looking into whether reports of infections in some places resulted from workers using laptops while traveling.

While the components and tactics of Flame were considered old-school, the gigantic virus's interchangeable software modules and targeted nature were evidence that malware is a potent weapon in the Internet era.

Computers infected with malware are typically programmed to reach out on the Internet to get updated orders from command servers controlled by hackers.

In this case, it appeared that Flame masters gave an order for the malware to vanish, leaving behind no trail that investigators might be able to follow or clues to its origin.

The self-destruct command was evidently sent after Flame was exposed and investigations commenced.

Infected computers that got the command went on to delete an array of files and then cram disks with random characters to thwart recovery of original code, according to security researchers.

It was unknown how many infected computers received the self-destruct command.

Flame was designed to suck information from computer networks and relay what it learned back to those controlling the virus. It can record keystrokes, capture screen images, and eavesdrop using microphones built into computers.

In an intriguing twist, the malware can also use Bluetooth capabilities in machines to connect with smartphones or tablets, mining contact lists or other information, according to security researchers. (SAN FRANCISCO - Agence France-Presse)

Use of Flame virus to deter Iran 'reasonable': Israel

Written By THA on Tuesday, 29 May 2012 | 10:59

For anyone facing the threat of a nuclear Iran, using cyberweapons such as the newly-discovered destructive virus known as Flame, would be a "reasonable" step, Israel's vice prime minister said on Tuesday.

"For anyone who sees the Iranian threat as significant, it is reasonable that he would take different steps, including these, in order to damage it," Strategic Affairs Minister Moshe Yaalon told Israel's army radio on Tuesday, just hours after the virus was discovered by Kaspersky Lab.

"Israel is blessed with being a country which is technologically rich, and these tools open up all sorts of possibilities for us," he said.

Late on Monday, Kaspersky Labs, a top Russian anti-virus firm said it had uncovered a new virus with unprecedented destructive potential, which was being used as a "cyberweapon" against several countries.

Kaspersky said the virus was several times larger than the Stuxnet worm that was discovered in June 2010 and used against the Iranian nuclear programme, with Israel widely suspected of involvement along with Western security agencies.

Flame is "actively being used as a cyber weapon attacking entities in several countries," a Kaspersky statement said, describing its purpose as "cyberespionage."

20 times larger than Stuxnet

"The complexity and functionality of the newly discovered malicious programme exceed those of all other cyber menaces known to date," it added.

It did not mention which country the virus was aimed at, but said the investigation began following complaints from the U.N.'s International Telecommunication Union about a piece of malware named Wiper, which was deleting sensitive information across the Middle East.

The malware code itself is 20MB in size - making it some 20 times larger than the Stuxnet virus.

According to Western media reports, Flame has been used to attack the Iranian oil ministry and Iran's main oil export terminal.

Kaspersky said Flame had been "in the wild" for more than two years, since March 2010. Officials with Symantec Corp and Intel Corp McAfee security division, the top 2 makers of anti-virus software, said they were studying Flame.

"It seems to be more complex than Duqu but it's too early to tell its place in history," said Dave Marcus, director of advanced research and threat intelligence with McAfee.

Most complex malicious software

Symantec Security Response manager Vikram Thakur said his company's experts believed there was a "high" probability that Flame was among the most complex pieces of malicious software ever discovered.

There is some controversy over who was behind Stuxnet and Duqu. Some experts suspect the United States and Israel, a view laid out in a January 2011 New York Times report that said they came from a joint program begun around 2004 to undermine what they said were Iran's efforts to build a bomb.

The U.S. Defense Department, CIA, State Department, National Security Agency, and U.S. Cyber Command declined to comment.

Hungarian researcher Boldizsar Bencsath, whose Laboratory of Cryptography and Systems Security first discovered Duqu, said his analysis showed that Flame may have been active for at least five years, perhaps even more than eight years.

That implies it was active long before Stuxnet.

"It's huge and overly complex, which makes me think it's a first-generation data gathering tool," said Neil Fisher, vice president for global security solutions at Unisys Corp. "We are going to find more of these things over time."

Prof Alan Woodward, from the Department of Computing at the University of Surrey said the attack was very significant. "This is basically an industrial vacuum cleaner for sensitive information," he told the BBC. He explained that unlike Stuxnet, which was designed with one specific task in mind, Flame was much more sophisticated. "Whereas Stuxnet just had one purpose in life, Flame is a toolkit, so they can go after just about everything they can get their hands on."

Once the initial Flame malware has infected a machine, additional modules can be added to perform specific tasks - almost in the same manner as adding apps to a smartphone. (ISTANBUL- Hürriyet Daily News)

UK News

Daha fazla haber
 
Support : Creating Website | Johny Template | Maskolis | Johny Portal | Johny Magazine | Johny News | Johny Demosite
Copyright © 2011. THA-Daily News - All Rights Reserved
Template Modify by Creating Website Inspired Wordpress Hack
Proudly powered by Blogger