First Published: 2012-06-11

 

After sparking cyber scare, Flame spy virus vanishes without trace

 

Flame masters give order for malware to vanish, leaving behind no trail that investigators might be able to follow or clues to its origin.

 

Middle East Online

By Glenn Chapman - SAN FRANCISCO

Mission accomplished

US computer security researchers said Sunday that the Flame computer virus that smoldered undetected for years in Middle Eastern energy facilities has gotten orders to vanish, leaving no trace.

Anti-virus company Symantec said in a blog post that late last week, some Flame "command-and-control servers sent an updated command to several compromised computers."

"This command was designed to completely remove (Flame) from the compromised computers."

Flame malicious software (malware) appears to have been "in the wild" for two years or longer and prime targets so far have been energy facilities in the Middle East, especially in Iran.

The discovery of Flame immediately sparked speculation that it had been created by US and Israeli security services to steal information about Iran's controversial nuclear drive.

Kaspersky Lab, one of the world's biggest producers of anti-virus software, said the Flame virus was "about 20 times larger than Stuxnet," the worm which was discovered in June 2010 and used against the Iranian nuclear program.

High concentrations of computers compromised by Flame were also found in Lebanon, the West Bank and Hungary. Additional infections have been reported in Austria, Russia, Hong Kong and the United Arab Emirates.

Compromised computers included many being used from home connections, according to security researchers who were looking into whether reports of infections in some places resulted from workers using laptops while traveling.

While the components and tactics of Flame were considered old-school, the gigantic virus's interchangeable software modules and targeted nature were evidence that malware is a potent weapon in the Internet era.

Computers infected with malware are typically programmed to reach out on the Internet to get updated orders from command servers controlled by hackers.

In this case, it appeared that Flame masters gave an order for the malware to vanish, leaving behind no trail that investigators might be able to follow or clues to its origin.

The self-destruct command was evidently sent after Flame was exposed and investigations commenced.

Infected computers that got the command went on to delete an array of files and then cram disks with random characters to thwart recovery of original code, according to security researchers.

It was unknown how many infected computers received the self-destruct command.

Flame was designed to suck information from computer networks and relay what it learned back to those controlling the virus. It can record keystrokes, capture screen images, and eavesdrop using microphones built into computers.

In an intriguing twist, the malware can also use Bluetooth capabilities in machines to connect with smartphones or tablets, mining contact lists or other information, according to security researchers.


 

Confrontation with Salafists looms in Tunisia: Who will blink first?

Russia gives Assad sophisticated missiles to repel enemies coming from afar

Bomb explodes near three embassies in Tripoli amid growing security fears

Attacks against mosques and husseiniyahs stoke Iraq fears of sectarian strife

Renewable energy drive gains pace in Morocco: Africa largest wind farm to open in 2014

Yemen blames jet crashes on ‘systematic sabotage' of air force

Qaeda takes no break in Yemen: Assassination of intelligence officer

Obama sways Erdogan on Russia-US brokered Syria conference

Absence of security as violence grips Libya’s Benghazi

‘People want to overthrow regime’ in Egypt

Ban, Lavrov call for urgent Syria conference

Bahrain forces raid home of top Shiite cleric

Iraq sectarian violence reaches new highs

Gruesome videos put Syria opposition in dire straits

Egypt police shut Rafah crossing to protest kidnappings

Four Syrian ministers, Nusra leader on US blacklist

Untold stories of Iraq war photographers

Tunisia President urges Salafists to condemn terror

Humanitarian crisis threatens Yemen transition

Obama: Assad departure is only way to resolve Syria crisis

Showdown nears: Tunisia Salafists defy government ban

Iraq PM blames bloodshed on sectarianism

Top US general in Iraq for security talks

Kuwait Airways to acquire 25 Airbus planes

Egypt leader holds crisis talks with ministers over kidnappings

Peace Now: Israel wants to 'legalise' wildcat settler outposts

Expats barred from morning treatment at Kuwait hospitals

Five hostages released in Yemen

US-led navies flex muscles in Gulf manoeuvres

White House releases Benghazi talking points emails

UN assembly condemns Assad 'escalation' of Syria war

After more than eight hours, IAEA-Iran nuclear talks fail again

Jubaland region gets ex-Islamist Somali warlord as President

Moscow: UN adds fuel to fire with approval of Arab-backed Syria resolution

Donors raise $2.6 billion to help Mali chase away ghost of war

Ghannouchi defies ‘his legitimate sons’: No to Salafist meeting in Kairouan

Will Western nations turn their back on Egypt’s Islamist President?

Bahrain follows in footsteps of Kuwait: Tweeters get jail term for ‘insulting King’

Extremism targets last liquor shops in Baghdad

Islamist radicals gear up for new show of force in Tunisia

Past mistakes in mind as Mali aid conference kicks off

Free Syrian Army vows to punish members involved in abuses

Iran in parallel nuclear talks amid low prospects for breakthrough

Better late than never: Palestinian rivals agree to form unity government

Promises ‘not kept’ to eradicate Casablanca's infamous slum