The Jerusalem Post
Jpost search icon google-icon iphone
  Set as Homepage
Wed, May 22, 2013   13 Sivan, 5773
newspapers magazines
 
    • Breaking News
    • Diplomacy & Politics
    • Defense
    • National
    • Mideast
    • Syria
    • Iran
    • World
    • Business
    • Sports
    • Health & Science
    • Environment
  • Video
  • Opinion
    • Columnists
    • Editorials
    • Op-Eds
    • Letters
  • Jewish World
  • Lifestyle
    • Arts & Culture
    • Food & Wine
    • Travel
  • Features
    • Insights & Features
    • Week in review
    • On the Web
    • Shalva Superheroes
    • Obama in Israel
  • Blogs
    • In the news
    • Judaism
    • From the Middle East
    • Lifestyle
    • Aliya
    • Science and Technology
  • JPost Apps
    • iPhone app
    • iPad app
    • Android app
    • Twitter
    • Facebook
    • RSS feeds
    • JPost Toolbar
    • JPost Newsletter
    • JPost Alert
  • Premium Zone
    • The Jerusalem Report
    • The Experts
    • 20 Questions
    • e-paper
    • Ivrit
    • Christian Edition
    • Dash
    • Magazine
    • Metro
    • In Jerusalem
  • French
    • Politique & Social
    • Affaires Palestiniennes
    • Diplomatie & Monde
    • Art & Culture
    • Israel
  • Green Israel
JPost Learn Hebrew  
Advertise with us  
Nefesh Guided Aliyah  
Eldan  
AFMDA  
Africa Israel Group  
Isram Group  
Kupat Ha  
JPost Twitter  
JPost Facebook  
Classifieds  
         
 
 
    
Breaking News
 
 
  • JPost.com
  • Middle East
 

New computer spying program linked to Flame authors

By REUTERS
10/16/2012 17:45
Tweet

"MiniFlame" software mimics older spying technology found largely in Iran and Sudan, but with surgical focus.

Stuxnet Virus
Stuxnet Virus Photo: Courtesy

SAN FRANCISCO - The security company that has discovered some of the most sophisticated spying software unearthed to date says it found a related program, dubbed "miniFlame," which can carry out more precise attacks on targets in the Middle East.

While the original Flame virus swept in data from perhaps 5,000 computers, largely in Iran and Sudan, the new miniFlame struck only about 50 "high-value" machines, according to Kaspersky Lab research published on Monday. Iran had previously blamed Flame for causing data loss on computers in the country's main oil export terminal and Oil Ministry.

  • UN agency plans major warning on Flame virus risk
  • 'Sons of Stuxnet' threaten energy infrastructure

"Flame acts as a long sword for broad swipes while miniFlame acts as a scalpel for a focused surgical dissection," Roel Schouwenberg, a senior researcher at Moscow-based Kaspersky Lab, told Reuters.

Kaspersky theorized that miniFlame was distributed mainly by Flame and another recently discovered spyware program, Gauss, which was most prevalent in Lebanon and may have been aimed at tracking financial transactions.

Not much is known about miniFlame's victims, except that they were more geographically dispersed than those of Flame and Gauss. Infections were found in Lebanon and Iran most of all but also in the Palestinian Territories, Iran, Kuwait, and Qatar, according to Kaspersky.

Kaspersky and US security software company Symantec Corp have said that some of the code in Flame also appeared in an early version of Stuxnet. Found in 2010 and aimed at Iran's nuclear enrichment program, Stuxnet is sometimes described as the first true cyber-weapon. Cyber experts widely believe Stuxnet is an American project.

Kaspersky and Symantec said in a joint research paper last month that Flame's control software remotely directed a number of smaller programs, and that the effects of only one of those programs was clear.

Symantec said at the time the overall project "fits the profile of military and intelligence operations," in part because encryption kept some operatives in the dark about what data they were taking from infected machines.

The many technological innovations in Flame included its hijacking of Microsoft Corp's Windows Update feature, which is critical for keeping the operating system current as new security problems come to light.

The new discovery concerns one of the smaller programs controlled by the Flame command software, referred to in the original code as SPE.

According to the Kaspersky analysis, it includes a "back door" allowing for remote control, data theft and the ability to take screen shots - or images of the computer screen - as the user engages with Microsoft Office, Adobe Systems Inc's Reader, web browsers, and other applications.

"MiniFlame is installed in order to conduct more in-depth surveillance and cyber-espionage," Kaspersky Chief Security Expert Alexander Gostev said.

Symantec said on Friday it had no new information on Flame or the related programs.

Kaspersky said that miniFlame worked with Flame and Gauss but could also operate independently of both, taking orders from a separate network of command computers. It said the new discovery makes a stronger case for the connection among all the programs, though it has not accused any party of authorship.

Kaspersky said it found six versions of miniFlame, the most recent created in September 2011. Some of the protocols it used dated to 2007, making it a long-running effort.

MiniFlame responded to a series of commands given Anglo first names by the program authors. "Elvis" created a process on an infected machine and "Barbara" took a screen shot. "Tiffany" directed the computer to a new command server.

In a speech on Thursday, US Secretary of Defense Leon Panetta warned that the country could act pre-emptively against imminent cyber attacks that would cause "significant physical damage" or kill US citizens. He said the Pentagon was rewriting its rules for engagement in cyberspace.

Though it has been ramping up its capabilities, the Pentagon has said little in public about what it can do.

  • Send
  • Large
  • Small
  • Print
  • Share
Most Viewed in
1
Erekat throws his weight behind Kerry's peace bid
2
'Chaos caused by Libyan war delays action in Syria'
3
PA official pours cold water on Kerry's visit
4
Activists: Hezbollah suffers big losses in Syria
JPost Community
Tweet
cyber espionage Stuxnet malware Flame miniFlame infrastructure cyberterrorism
Share this article
Tweet
Share
Send
Your comment must be approved by a moderator before being published on JPost.com. Disqus users can post comments automatically.

Comments must adhere to our Talkback policy. If you believe that a comment has breached the Talkback policy, please press the flag icon to bring it to the attention of our moderation team.
JPost Services
conferenceConference
newsletterNewsletter
iphoneMobile Apps
kotelcamKotel Cam
kolboJPost Alert
premiumPremium
JPost TV News  
Mobile Apps  
Bank Hapoalim  
Meir Panim  
Yad Ezra  
Rambam Hospital  
TourLuxe  
Zev Goldstein PLLC  
Penrose Gallery  
JPost Premium Zone  
JPost kotel Camera  
         
 
Israel Focus
JPost TV News
Coming soon to a screen near you!  
Nefesh B'Nefesh Guided Aliyah
Already living in Israel? Enjoy the Benefits of Aliyah!  
Give "Freedom" this Passover
to needy Israeli families. Donate now  
War Threatens
Protect the People of Northern Israel  
Intelligence Squared
The international debate forum, announces it is coming to Israel  
Bank Hapoalim
Israeli's number one bank  
Jerusalem Post Lite
Lite Edition of the Jerusalem Post for English improvement  
Learn Hebrew with us
Get 10 minutes free personal coaching in Hebrew through phone or Skype  
JPost newspapers
Sign up for the JPost newspapers and receive one month free subscription  
Kosher English Magazine
English language weekly magazine - especially for religious people  
JReport Kindle Edition
Now you can get the Jerusalem Report directly to your Kindle  
JPost Premium Edition
The very best articles are available only in our Premium edition  
Lifestyle Magazine
 
 
Real Estate
Don't Look For a House!
In Israel, our website will do it for you!  
 
Travel
Eldan Rent a Car
20% off all Car Rental Reservations in Israel  
Hertz Car Rental
Special Online Discounts!  
The King David Jerusalem Hotel
One of the world's truly iconic hotels, and a Jerusalem landmark  
 
 
 

Sites Of Interest:

Jerusalem Hotels
KKL-JNF
Poalim Online
BreitBart.com
Our Friends
Jerusalem Attractions
Jerusalem Tours
itraveljerusalem.com

JPost sites:

Learn Hebrew
The Jerusalem Report
Our Magazines
JPost Edition Francaise
Green Israel
Christian World
Jerusalem Post Lite

Services:

JPost Mobile Apps
JPost Premium
JPost Newsletter
JPost Toolbar
JPost News Ticker
JPost RSS feeds
JPost Archives
JPost Alert
JPost Kotel Cam

JPost Conferences:

NYC Conference
Diplomatic Conference

Information:

About Us
Feedback
Staff E-mails
Copyright
Sitemap
News Partners
Advertise with Us
Price List
Statistics
Ad Specs
Terms Of Service
Jpost.com, the online edition of the Jerusalem Post Newspaper - the most read and best-selling English-language newspaper in Israel. For analysis and opinion from Israel, the Jewish World and the Middle East. Jpost.com offers expert and in-depth reporting from Israel, the Jewish World and the Middle East, including diplomacy and defense, the Palestinian-Israeli conflict, the Arab Spring, the Mideast peace process, politics in Israel, life in Jerusalem, Israel's international affairs, Iran and its nuclear program, Syria and the Syrian civil war, Lebanon, the Palestinian Authority, the West Bank and Gaza Strip, Israel's world of business and finance, and Jewish life in Israel and the Diaspora.
 
About Us | Advertise with Us | Subscribe | Premium | Newsletter | RSS | Contact Us
 
All rights reserved © The Jerusalem Post 1995 - 2012