PDA

View Full Version : New malware to know about but confined to Mideast and Africa, so far



razz
5-29-12, 10:47am
Just to keep the info loop going, it seems that this is something different, not from hackers and intelligence purposes.
http://www.cbc.ca/news/technology/story/2012/05/28/tech-malware-flame-cyberattack.html
It has been around for about 1-2 years apparently but the detection has seemingly been more recent.
Quote:
Kaspersky has so far identified seven countries that have been affected by Flame attacks:
Iran (189 infections)
Israel and Palestine (98 targets)
Sudan (32 targets)
Syria (30 targets)
Lebanon (18 targets)
Saudi Arabia (10 targets)
Egypt (5 targets)

The Hungarian experts found that the worm, which they traced under the filename wavesup3.drv, was active in several European countries, including Hungary, as well as the United Arab Emirates and Iran.

Variety of targets

So far, there doesn't seem to be a pattern to the types of targets attacked. Individuals, educational institutions and state-related organizations have all been hit, Gostev said.

Alan
5-31-12, 3:44pm
It looks like this piece of intelligence gathering spyware was commissioned by the same group that created Stuxnet (http://en.wikipedia.org/wiki/Stuxnet) a few years ago. Where Stuxnet was designed to disrupt specific machinery involved in Iran's nuclear program, it looks like this bit of code, named Flame (http://www.cio-today.com/news/Virus-Briefly-Hits-Iran-s-Oil-Industry/story.xhtml?story_id=13300BUWGIYK) was designed to collect information from computers, attached devices and bluetooth devices near the affected computer.

It's rather brilliant actually, doing the work of thousands of human spies, remotely.