Kaspersky Lab and Iran’s national computer emergency response team revealed Flame, a highly complex espionage toolkit found mainly on computers in Iran and elsewhere in the Middle East. Kaspersky said its complexity exceeded that of any other known threat at the time.
What happened
- At around 20MB, Flame was many times larger than typical malware.
- It could record audio through microphones, capture screenshots, gather passwords, and send files to remote servers.
- Researchers believed it had been active for at least two years before discovery, evading the antivirus products in use by victims.
- Analysts linked it to the developers of Stuxnet and Duqu; later media reports said it was developed by the US and Israel, which did not confirm this.
Why it mattered
Flame showed the scale and sophistication of state-grade espionage tools. It also used a forged Microsoft certificate to spread, prompting an emergency Microsoft update.
Lessons for organisations
Code-signing trust can be abused, so monitor for unusual software updates and keep certificate revocation lists current. Endpoint detection and network monitoring help catch covert data exfiltration, such as unexpected uploads to unfamiliar servers.
Sources: CNN Money, Securelist (Kaspersky)
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.