Powerful "Flame" cyber weapon found in Middle East

Hanna 1

New member
Pro User
Local time
9:36 PM
Messages
338
Location
Beirut
Security experts have discovered a new data-stealing virus dubbed "Flame" they say has lurked inside thousands of computers across the Middle East for as long as five years as part of a sophisticated cyber warfare campaign.
It is the most complex piece of malicious software discovered to date, said Kaspersky Lab security senior researcher Roel Schouwenberg, whose company discovered the virus. The results of the Lab's work were made available on Monday.

Powerful "Flame" cyber weapon found in Middle East - Technology & science - Security - msnbc.com
 

My Computer My Computer

At a glance

win7 home premium-64bit-SP1-IE10T6600 2.2Ghz4 GbATI Mobility Radeon HD 4530
Computer type
Laptop
Computer Manufacturer/Model Number
HP pavilion DV6
OS
win7 home premium-64bit-SP1-IE10
CPU
T6600 2.2Ghz
Motherboard
HP Model 3628
Memory
4 Gb
Graphics Card(s)
ATI Mobility Radeon HD 4530
Sound Card
IDT High Definition
Screen Resolution
1366x768 @ 60Hz
Hard Drives
500Gb Western Digital
Antivirus
MSE
Other Info
Malwarebytes Antimalware + Spybot-Search&Destroy

My Computer My Computer

At a glance

Windows 7 Ultimate X64 SP1Intel i5-2550K, Differing ~4.4-4.8GHz No buil...16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GBASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built Desktop By DataTech
OS
Windows 7 Ultimate X64 SP1
CPU
Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU
Motherboard
ASUS P8Z68-V PRO/GEN3
Memory
16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GB
Graphics Card(s)
ASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Sound Card
Onboard Realtek 5-1
Monitor(s) Displays
Samsung P2570HD
Screen Resolution
1920x1080
Hard Drives
Samsung 840 Pro 256GB SSD for OS, 500GB Seagate Constellation (Enterprise drive) for Data
PSU
Corsair HX650W
Case
Inwin Dragon Rider
Cooling
Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM
Keyboard
E-Z Eyes, bright yellow keys with large characters
Mouse
steelseries SENSEI Laser Pro Gaming
Internet Speed
48-51Mbs Mbs down, 11 Mbs up Xfinity Cable
Antivirus
Norton Internet Security 2013
Browser
IE 10, Opera, Pale Moon if needed
Other Info
4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power supply, 1.21 gigawatts.

My Computer My Computer

At a glance

Windows 10 Home x64INTEL Core i5-750 Quad-Core 3.37GHzHyperX Fury Black Series 8GB (2 x 4GB) 1866MhzEVGA GeForce GTX 750 Superclocked 1GB 128-Bit...
Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
Meet ‘Flame,’ The Massive Spy Malware Infiltrating Iranian Computers

The researchers say they don’t know yet how an initial infection of Flame occurs on a machine before it starts spreading. The malware has the ability to infect a fully patched Windows 7 computer, which suggests that there may be a zero-day exploit in the code that the researchers have not yet found.

Flame appears to have been operating in the wild as early as March 2010, though it remained undetected by antivirus companies.


Source: Wired

edit - thanks for moving my post to this thread - I did a forum search but failed to find mention of the story.
 

My Computer My Computer

At a glance

W7 Pro SP1 64biti78GBIntel HD Graphics
Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
...still on vacation, but with all the rain, I've had some reading time. Biggest point of this is; between Flame and Stuxnet both being, what, 5 years old...
You gotta wonder, what's been planted since?

Great reading.
 

My Computer My Computer

At a glance

Windows 7 Home Premium x64Intel 2500k @4.5ghz 66deg max P95/IBT8 Gigs Patriot Viper 2 Extreme @1600EVGA GTX 580 3 GIG 35degrees idle
Computer Manufacturer/Model Number
Home Made
OS
Windows 7 Home Premium x64
CPU
Intel 2500k @4.5ghz 66deg max P95/IBT
Motherboard
Gigabyte Z68A-D3-B3
Memory
8 Gigs Patriot Viper 2 Extreme @1600
Graphics Card(s)
EVGA GTX 580 3 GIG 35degrees idle
Sound Card
Nvidia HD audio via HDMI to 7.1 Receiver
Monitor(s) Displays
32" Olevia hdtv
Screen Resolution
1080p
Hard Drives
64gig SSD(OS/Apps)
250gig (Files and Dox)
1tb (imaging and backup)
PSU
Corsair vx550w
Case
Thermaltake V3 black
Cooling
CM 212+(push n pull) 4 case fans
Keyboard
Logitech wireless Combo, G13
Mouse
G300
Internet Speed
40mps
Other Info
Two others up and running; C2D E5200/MSI G41M-P26/Corsair XMS3 8gb/GTS 250 1gb and C2D E8200/xFx 750sli/8gb Corsair Dominator/2x EVGA 550ti
Working on; i2600 Build...
HP DV6
@Work I use a Lenovo 5536B8U + Lenovo U300s
UPDATED: Cyber Espionage Reaches New Levels with Flamer

Removal Tool in link

Download the 32-bit or
the
64-bit
removal
tools and find out if you’re infected with Flamer, the world’s
most discrete and dangerous piece of malware ever. If you are already protected by a Bitdefender security solution, you do not need to run the removal tool.

Update 2: As we’re digging into Flamer.A, new details about the piece’s modus operandi surface. The team working on it have uncovered that several components use an internal list called NetworkTypeIdentifier. This list references high-profile web sites such as *.overture.* , *.gmail.*, *.hotmail.* , *.bbc.co.* , *.bbc.co.* that are probed in order to get information about the bandwidth capabilities of the connection. However, the list also references three Iranian websites (*.baztab.* , *.maktoob.* , *.gawab.*) , which confirms once again that Iran was one of the designated targets.

Closer inspection of the EUPHORIA module revealed that it controls the spreading mechanism via USB sticks. The USB spreading capabilities are re-enforced with a secondary component called AUTORUN_INFECTOR that is being used to exploit the operating system’s Autorun feature.
[fragment of the configuration file for the EUPHORIA module]
EUPHORIA.PayloadNamesList.1.data.PayloadName string Lss.ocx
EUPHORIA.PayloadNamesList.2.data.PayloadName string System32.dat
EUPHORIA.PayloadNamesList.3.data.PayloadName string NtVolume.dat

Source

Everything You Need to Know About Flamer.A – World’s Most Sophisticated Cyber-Weapon

In 2010, the world stopped spinning for a moment, as evidence of a highly complex piece of malware hitting a nuclear research facility in Iran started to emerge. Two years later, the discovery of another e-threat shows that the team behind Stuxnet and Duqu had another offspring that was even more complex and persistent.

Source

A Guy
 

My Computer My Computer

At a glance

Windows 10 Home x64INTEL Core i5-750 Quad-Core 3.37GHzHyperX Fury Black Series 8GB (2 x 4GB) 1866MhzEVGA GeForce GTX 750 Superclocked 1GB 128-Bit...
Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi

My Computer My Computer

At a glance

Windows 7 Ultimate 64bitIntel Core i7-2600K Sandy Bridge 3.4GHz (@4.5...G.SKILL Ripjaws X Series 16GB 1600Mhz (4 x 4G...x2 EVGA GeForce GTX 760's w/ACXCoolers in SLI...
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Jeepmann/Custom Built
OS
Windows 7 Ultimate 64bit
CPU
Intel Core i7-2600K Sandy Bridge 3.4GHz (@[email protected])
Motherboard
Asus Maximus IV Extreme LGA 1155 Intel P67
Memory
G.SKILL Ripjaws X Series 16GB 1600Mhz (4 x 4GB) (Stock)
Graphics Card(s)
x2 EVGA GeForce GTX 760's w/ACXCoolers in SLI Surround
Sound Card
On-Board
Monitor(s) Displays
3x Acer 24" HDMI Widescreen LCD Monitor
Screen Resolution
3@ 1920x1080 (5760x1080 In Surround)
Hard Drives
Samsung 830 128gb ssd
Western Digital Caviar Black 640GB 7200 RPM
Western Digital Caviar Black 500GB 7200 RPM
Seagate 2tb 7200 RPM
PSU
COOLER MASTER Silent Pro 1000W
Case
COOLER MASTER HAF X Black
Cooling
CORSAIR Hydro H70
Keyboard
Logitech G510
Mouse
Zalman M300
Internet Speed
100mbps-ish Down & 5mbps-ish Up
Other Info
I installed the stock 140mm case fan outside of case then installed the H70+ 1 of its 120mm fans inside case. Used the 2nd 120mm from the H70 to go in the Gpu tunnel.
230mm Front,200mm side,200mm top,120mm Gpu tunnel,120mm&140mm on H70.

My Computer My Computer

At a glance

Windows 7 Ultimate X64 SP1Intel i5-2550K, Differing ~4.4-4.8GHz No buil...16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GBASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built Desktop By DataTech
OS
Windows 7 Ultimate X64 SP1
CPU
Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU
Motherboard
ASUS P8Z68-V PRO/GEN3
Memory
16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GB
Graphics Card(s)
ASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Sound Card
Onboard Realtek 5-1
Monitor(s) Displays
Samsung P2570HD
Screen Resolution
1920x1080
Hard Drives
Samsung 840 Pro 256GB SSD for OS, 500GB Seagate Constellation (Enterprise drive) for Data
PSU
Corsair HX650W
Case
Inwin Dragon Rider
Cooling
Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM
Keyboard
E-Z Eyes, bright yellow keys with large characters
Mouse
steelseries SENSEI Laser Pro Gaming
Internet Speed
48-51Mbs Mbs down, 11 Mbs up Xfinity Cable
Antivirus
Norton Internet Security 2013
Browser
IE 10, Opera, Pale Moon if needed
Other Info
4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power supply, 1.21 gigawatts.
Computer virus briefly hits Iran's oil industry

TEHRAN, Iran (AP) — Iran's key oil industry was briefly affected by the powerful computer virus known as "Flame" that has unprecedented data-snatching capabilities and can eavesdrop on computer users, a senior Iranian military official said Wednesday.

Computer virus briefly hits Iran's oil industry - Yahoo! News
 

My Computer My Computer

At a glance

win7 home premium-64bit-SP1-IE10T6600 2.2Ghz4 GbATI Mobility Radeon HD 4530
Computer type
Laptop
Computer Manufacturer/Model Number
HP pavilion DV6
OS
win7 home premium-64bit-SP1-IE10
CPU
T6600 2.2Ghz
Motherboard
HP Model 3628
Memory
4 Gb
Graphics Card(s)
ATI Mobility Radeon HD 4530
Sound Card
IDT High Definition
Screen Resolution
1366x768 @ 60Hz
Hard Drives
500Gb Western Digital
Antivirus
MSE
Other Info
Malwarebytes Antimalware + Spybot-Search&Destroy
Brilliant, such a dangerous weapon it sat on computers for 5+ years doing nothing, not even alerting anyone to it's potential existance. Flame? no, damp squibb.
 

My Computer My Computer

At a glance

Windows 7 home premium x64AMD FX-4100 AM3+ 3.6GHz 12MB Black EditionCrsair vengeance 12Gb DDR3 1600MHz CL9Asus GTX 560 1GB
Computer Manufacturer/Model Number
DIY
OS
Windows 7 home premium x64
CPU
AMD FX-4100 AM3+ 3.6GHz 12MB Black Edition
Motherboard
Asus M5A97 Pro
Memory
Crsair vengeance 12Gb DDR3 1600MHz CL9
Graphics Card(s)
Asus GTX 560 1GB
Sound Card
Realtek onboard
Monitor(s) Displays
Hanns G 1680x1050 native
Hard Drives
OCZ 128Gb Petrol ssd
2x500 Gb Samsung
PSU
OCZ StealthXstream II 500W
Internet Speed
8Mb or better
It's surprising it was discovered I think since Flame and variants targeted Oil production, power plants, weapons, plutonium inventories, and nuclear facilities.
 

My Computer My Computer

At a glance

Windows 7 Ultimate X64 SP1Intel i5-2550K, Differing ~4.4-4.8GHz No buil...16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GBASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built Desktop By DataTech
OS
Windows 7 Ultimate X64 SP1
CPU
Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU
Motherboard
ASUS P8Z68-V PRO/GEN3
Memory
16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GB
Graphics Card(s)
ASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Sound Card
Onboard Realtek 5-1
Monitor(s) Displays
Samsung P2570HD
Screen Resolution
1920x1080
Hard Drives
Samsung 840 Pro 256GB SSD for OS, 500GB Seagate Constellation (Enterprise drive) for Data
PSU
Corsair HX650W
Case
Inwin Dragon Rider
Cooling
Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM
Keyboard
E-Z Eyes, bright yellow keys with large characters
Mouse
steelseries SENSEI Laser Pro Gaming
Internet Speed
48-51Mbs Mbs down, 11 Mbs up Xfinity Cable
Antivirus
Norton Internet Security 2013
Browser
IE 10, Opera, Pale Moon if needed
Other Info
4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power supply, 1.21 gigawatts.
FLAMES NEWS
Was Flame virus written by cyberwarriors or gamers?
Why would super-secret spy software be written in a video game language? As security researchers continue to unpack the digital mystery that is the Flame virus, that's just one question looming over perhaps the world's most intriguing digital whodunit.
READ MORE
Red Tape - Was Flame virus written by cyberwarriors or gamers?

So, TAKE CARE GAMERS
 

My Computer My Computer

At a glance

win7 home premium-64bit-SP1-IE10T6600 2.2Ghz4 GbATI Mobility Radeon HD 4530
Computer type
Laptop
Computer Manufacturer/Model Number
HP pavilion DV6
OS
win7 home premium-64bit-SP1-IE10
CPU
T6600 2.2Ghz
Motherboard
HP Model 3628
Memory
4 Gb
Graphics Card(s)
ATI Mobility Radeon HD 4530
Sound Card
IDT High Definition
Screen Resolution
1366x768 @ 60Hz
Hard Drives
500Gb Western Digital
Antivirus
MSE
Other Info
Malwarebytes Antimalware + Spybot-Search&Destroy

My Computer My Computer

At a glance

64-bit Windows 11 Pro for WorkstationsIntel i7-8700K OC'd to 5 GHz64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600...ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone

My Computer My Computer

At a glance

win7 home premium-64bit-SP1-IE10T6600 2.2Ghz4 GbATI Mobility Radeon HD 4530
Computer type
Laptop
Computer Manufacturer/Model Number
HP pavilion DV6
OS
win7 home premium-64bit-SP1-IE10
CPU
T6600 2.2Ghz
Motherboard
HP Model 3628
Memory
4 Gb
Graphics Card(s)
ATI Mobility Radeon HD 4530
Sound Card
IDT High Definition
Screen Resolution
1366x768 @ 60Hz
Hard Drives
500Gb Western Digital
Antivirus
MSE
Other Info
Malwarebytes Antimalware + Spybot-Search&Destroy
Back
Top