Forgot your password?

typodupeerror
Security IT

Flame Malware Authors Hit Self-Destruct 260

Posted by samzenpus
from the without-a-trace dept.
angry tapir writes "The creators of the Flame cyber-espionage threat ordered infected computers still under their control to download and execute a component designed to remove all traces of the malware and prevent forensic analysis. Flame has a built-in feature called SUICIDE that can be used to uninstall the malware from infected computers. However, late last week, Flame's creators decided to distribute a different self-removal module to infected computers that connected to servers still under their control."
This discussion has been archived. No new comments can be posted.

Flame Malware Authors Hit Self-Destruct

Comments Filter:
  • by Anonymous Coward on Thursday June 07, 2012 @10:22PM (#40252571)

    No need to wipe the files if no one knows they're there.

  • Re:No AutoDestruct (Score:5, Insightful)

    by nanoflower (1077145) on Thursday June 07, 2012 @10:36PM (#40252669)
    All too true. I'm sure the authors will be taking that into account for their next version. Hopefully everyone will be on the lookout and catch it quicker than they did this one.
  • Re:No AutoDestruct (Score:5, Insightful)

    by Anonymous Coward on Thursday June 07, 2012 @10:37PM (#40252677)

    That doesn't sound like a very effective worm. If they did it that way you could fix the infection with a pf rule.

  • by tick-tock-atona (1145909) on Thursday June 07, 2012 @10:42PM (#40252699)

    Not only does Flame use a previously unknown MD5 chosen prefix attack [arstechnica.com], but now they are removing all traces of the software from machines under their control.

    Now, since security researchers already have copies of the software this isn't going stop anyone further deconstructing and analysing it. The only possible reason for doing this is to avoid discovery of infection somewhere particularly sensitive. I wonder who the lucky person or nation-state is?

  • Yes, "Lucky" (Score:5, Insightful)

    by SuperKendall (25149) on Thursday June 07, 2012 @10:47PM (#40252737)

    The only possible reason for doing this is to avoid discovery of infection somewhere particularly sensitive.

    Or, to make everyone else stop looking.

    You know all of the installations received the same self-destruct command how again?

  • by TheEyes (1686556) on Thursday June 07, 2012 @10:59PM (#40252825)

    Why do companies outsource their factories to China? Why did AIG and several other companies leverage themselves to several times what they were worth?

    Birds gotta fly. Fish gotta swim. Pointy-haired bosses gotta sacrifice the future for a monetary bonus today.

  • Re:Interesting (Score:2, Insightful)

    by bmo (77928) on Thursday June 07, 2012 @11:04PM (#40252849)

    The teenage hacker in a basement was never as much of a risk compared to what started happening about 15 years ago with organized crime getting involved.

    This "new" kind of malware has been dubbed (I think more accurately than most) crimeware.

    And whether governments do it, or the RBN, it's still crimeware.

    --
    BMO

  • by gman003 (1693318) on Thursday June 07, 2012 @11:04PM (#40252851)

    You know what's more interesting?

    Heckler und Koch GmbH and Rheinmetal AG have licensed factories in Iran. Iranian factories are cranking out G3s, MP5s, MG3s, all legally and for export. Not to mention the various Chinese/Russian small arms they manufacture (couldn't find out whether those were licensed or not).

    I think that, before they ban software companies from doing business in Iran, they should maybe think about banning the firearm companies. Just a thought.

  • by Billly Gates (198444) on Thursday June 07, 2012 @11:13PM (#40252897) Homepage Journal

    The more I learn about Flame the more it amazes me.

    Arstechnica.com has more stories on it and how it worked through collision detection and much more. I am amazed yet worried as I am sure malware mobfia folks are using the source code with real NATO grade malware complete with forging certificates, turning zombies into proxy servers, and using the Md5 collision detection done by professional mathematicians.

    Worse Ubuntu and other operating systems can be hit by this as they use the same algorithms for the certificates. This piece of malware was just done through conventional 0 day exploits but rather a very sophisticated means of forging certificates and might have done the cyberworld much more harm.

  • by fullback (968784) on Thursday June 07, 2012 @11:36PM (#40253009)

    Because there is no legitimate reason to not do business. The relentless war mongering against fictional bogeymen is fascinating, too.

  • Re:Interesting (Score:5, Insightful)

    by flyingsquid (813711) on Thursday June 07, 2012 @11:41PM (#40253045)

    Something tells me that this wasn't designed by a teenager.

    There are a limited number of possible suspects. First off, not many parties have the means to create this. The consensus is that Flame is one of the largest and most advanced pieces of malware ever created- it's 20 megabytes of code- which strongly implies that it was developed by a nation with an advanced cyber-warfare capability. That list is pretty short, and would include countries like the United States, China, Russia, Israel, and North Korea.

    Second, let's look at the targets. The Flame malware hit Iran, Israel/Palestine, Sudan, Syria, Lebanon, Saudi Arabia, and Egypt, in that order. Roughly half of the infections are in Iran. So whoever created Flame is worried about the Middle East, but really, really worried about Iran. More worried about Iran than any other country. The Iran fixation suggests two possible suspects- Israel and the United States.

    The focus on Iran is consistent with Flame coming from the U.S., but Flame also targets several U.S. allies, including Egypt and Saudi Arabia. The other thing is, Flame doesn't target anything outside of the Middle East. If it was produced by the U.S., you'd expect Flame to be found in other countries- North Korea and Pakistan, for example- where the U.S. has security interests. But whoever created Flame doesn't really care what happens in North Korea or Pakistan. Whoever created Flame is primarily concerned with countries that are either enemies or potential enemies of Israel- Iran, Palestine, Syria, Lebanon. That strongly suggests Israel as the culprit.

  • by Sir_Sri (199544) on Thursday June 07, 2012 @11:48PM (#40253093)

    1. Because iran has money.
    2. Because there are 70 million people in Iran, the vast majority of whom are not engaged in trying to kill americans or europeans.
    3. Because lots of people, especially in europe, believe that US sanctions are counter productive, and so don't have such sanctions.

    Also keep in mind there are lots of things that aren't barred from export to Iran, and lots of things are sold legally to other countries and then illegally re-exported to Iran. Most notably to qatar and bahrain, but other places as well.

  • by Gr8Apes (679165) on Friday June 08, 2012 @12:09AM (#40253195)
    all true, which is why you keep multiple backups dating back months, right?
  • ... it is way too late to get rid of the evidence. I mean, really? Every malware researcher ever must now have a copy of the code.

  • Re:Interesting (Score:5, Insightful)

    by viperidaenz (2515578) on Friday June 08, 2012 @12:45AM (#40253371)
    ... because small groups of smart people can't create something complex? It's software, you don't need massive amounts of funding, all you need is a few smart people and some time.
  • Re:In that order (Score:4, Insightful)

    by Bevilr (1258638) on Friday June 08, 2012 @01:33AM (#40253609)
    Have you bothered to read other articles on Flame? It's ability to record and gather information and transmit it back to C&C servers means that it's an excellent tool not just to do large government espionage, but also to listen in on individual conversations. As a tool in a fight against domestic terrorism, and counter espionage. I imagine it would be very effective, it's like a wiretap, without having to ask a judge for a wiretap. Infections in Israel/Palestine aren't broken down by Israel vs Palestine anywhere I've seen, which may mean that the vast majority are in Palestine. If that's true, it is another pretty large piece of evidence in favor of Israeli authorship.
  • Re:In that order (Score:4, Insightful)

    by sortadan (786274) on Friday June 08, 2012 @02:52AM (#40253921)
    Why would you think that they wouldn't spy on their own people, especially with their relationship to the Palestinians? If anything, the fact that it's not showing up in the US would tend to prove the point that it was Israel. The US clearly [slashdot.org] isn't afraid to spy on it's own people.
  • by Anonymous Coward on Friday June 08, 2012 @03:21AM (#40254025)

    ... it is way too late to get rid of the evidence. I mean, really? Every malware researcher ever must now have a copy of the code.

    The code, sure. But there is still value in hiding what data has been stolen. Destroying the evidence rather than deleting it in a recoverable way means that if a target realises they were infected they will have to assume that everything was taken. That's much worse than knowing exactly what was taken. Consider online store that keeps credit card details for a million users - the difference between knowing that 20 credit card details were leaked and merely knowing that you were infected could well be the difference between surviving as a company or not.

  • Re:In that order (Score:5, Insightful)

    by slashmojo (818930) on Friday June 08, 2012 @03:43AM (#40254099)

    By the same reasoning it could have been made by Iran..

  • by DarkOx (621550) on Friday June 08, 2012 @05:37AM (#40254519) Journal

    Right but the assumption has always been they don't vandalize their own bots because the owners would then discover they are part of a bot net. That does not hold if the bot net owner is already dismantling the network, I don't know what motivation they have to not nuke the hosts entirely to ensure there don't leave any finger prints.

    The only thing I can think of is they may be concerned that if a large percentage of the public has their machines trashed all at the same time Joe Sixpack of Pakistani mangoes might wake up and start taking computer security seriously. Which could make future bot nets harder to construct.

Blessed is he who expects nothing, for he shall never be disappointed. -- Alexander Pope

Working...