Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Don't ya wish your boyfriend was a geek like me?.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. Visual C++ Redistributable Runtimes AIO Repack
5. Visual C++ Runtime Installer (All-In-One)
6. McAfee Removal Tool (MCPR)
7. MusicBee
8. Rufus
9. K-Lite Mega Codec Pack
10. Sergei Strelec's WinPE
More >>

top reads

Star How to Disable 1-Click Ordering on Amazon (and Avoid Surprise Charges)

Star How to Fix Shallow Paint Layer Depth in Bambu Studio

Star Aviator Betting Game Secrets: Unlock 97% RTP & Triple Your Wins

Star Windows Recall: What It Is, Why Hackers Will Love It, and How to Stay Safe

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star How To Use VLC Media Player to Trim Video Clips

Star What Is the $WinREAgent Folder and Can I Delete It?

Star Swear Your Way to Better Search Results

Star How to Get a Dark Start Menu and Taskbar in Windows 10 & 11

Star Enable, Disable, Manage, Delete or Create a System Restore Point


MajorGeeks.Com » News » October 2012 » miniFlame: the Flame trojan's little brother

miniFlame: the Flame trojan's little brother


Contributed by: Email on 10/17/2012 03:26 PM [ comments Comments ]


Kaspersky Lab has detailed a small, highly-specialized trojan that has been identified as belonging to the Flame spyware worm family. The trojan, which has been dubbed "miniFlame", was discovered during the investigations into Flame, Gauss and Duqu in early July 2012.

Kaspersky Lab said that the discovered malware was initially believed to be an early version of Flame, but, following a detailed analysis of the protocols involved, this assumption turned out to be wrong. miniFlame is a separate spyware trojan and was apparently created in the same trojan lab which built Flame and Gauss. The researchers believe that it was developed in parallel with these trojans in 2010 and 2011.

Kaspersky's analysis concludes that miniFlame plays a special role within the Flame family. While it is functional as a stand-alone trojan, it can also be used as a plugin for Flame and Gauss. This means that Flame and Gauss can load miniFlame, for example, in order to obtain direct access to the infected computer.

An attack involving Flame, Gauss and miniFlame probably plays out like this: first, Flame and Gauss are used to infect as many targets as possible. Then, the attackers harvest their victims' data and use this data to identify targets that could be particularly worthwhile. As the last step, the chosen victims can then be spied on by the miniFlame trojan on a continuing basis.

The specialized nature of miniFlame is reflected in the statistics the researchers collected: Kaspersky has registered Flame and Gauss on about 10,000 systems in the Middle East, while miniFlame has only been found on "a few dozen systems in Western Asia". This confirms Kaspersky's suspicion that miniFlame is being used as a "high precision espionage tool".

However, the company's analysis is not yet complete. The experts believe that further trojan variants exist because the command & control servers "speak" three different protocols. One communicates with Flame and the second with miniFlame, but the communication partner of the third one hasn't been identified yet. Kaspersky is currently using the name "IP" for this "Higgs trojan". It has been attributed to the same trojan lab that also created Flame, Gauss and miniFlame.

Kaspersky says that the new findings around Flame, Gauss and miniFlame have "probably only scratched the surface" of the massive cyber-spy operation that seems to be ongoing in the Middle East. The analysis was carried out on behalf of the International Telecommunication Union (ITU). The German Federal Office for Information Security (BSI) was also involved in the investigation; however, the BSI refused to comment when asked about the precise nature of its involvement by The H's associates at heise Security.






« Nitol Botnet Shares Code with Other China-Based DDoS Malware · miniFlame: the Flame trojan's little brother · Daily Reviews Summary 10/18/12 @ NT Compatible »




Comments
comments powered by Disqus

MajorGeeks.Com » News » October 2012 » miniFlame: the Flame trojan's little brother

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition