A mystery computer virus discovered last month and deployed in a massive cyberattack chiefly against Iran sought to steal designs and PDF files from its victims, a Russian firm said.
Kaspersky Lab, one of the world’s biggest producers of anti-virus software, announced last month the discovery of the Flame virus, which it described as the biggest and most sophisticated malware ever seen.
In the latest update on Kaspersky’s analysis of the virus, released late on Monday, the firm’s chief security expert, Alexander Gostev, said the malware’s creators had focussed on file formats such as PDF and AutoCAD, a software for computer design and drawing.
“The attackers seem to have a high interest in AutoCAD drawings,” Gostev said in a statement.
The malware also “goes through PDF and text files and other documents and makes short text summaries,” he added.
“It also hunts for e-mails and many different kinds of other ‘interesting’ [high-value] files that are specified in the malware configuration,” he said.
He confirmed that Iran was by far the biggest target with a count of 185 infections, followed by 95 in Israel and the Palestinian Territories, 32 in Sudan and 29 in Syria.
The discovery of Flame immediately sparked speculation that it had been created by US and Israeli security services to steal information about Iran’s controversial nuclear drive.
Intriguingly, Kaspersky said that hours after the existence of the virus was first announced on May 28, “The Flame command-and-control infrastructure, which had been operating for years, went dark.”
It gave no further information over the possible perpetrators of the mystery attack, though it identified about 80 domains that appear to belong to the Flame infrastructure, in locations from Hong Kong to Switzerland.
Kaspersky said it had used a procedure known as sinkholing — which allows Internet security experts to gain control of a malicious server — to analyze the operation.
During the sinkholing it found that on three computers in Lebanon, Iraq and Iran the Flame versions changed, suggesting Flame upgraded itself in the process.
Meanwhile, Microsoft Corp has warned that a bug in Windows allowed PCs across the Middle East to become infected with the Flame virus and released a software fix to fight it.
A spokeswoman for Microsoft declined to comment on whether other viruses had exploited the same flaw in Windows or if the company’s security team was looking for similar bugs in the operating system.
Flame’s code included what is known as a digital certificate, which falsely identified it as a piece of software from Microsoft.
A bug in Terminal Services licensing allowed the hackers to use it to create fake certificates that identified Flame as being from Microsoft, Mike Reavey, a senior director with Microsoft’s Security Response Center, said in a blog post.
“We continue to investigate this issue and will take any appropriate actions to help protect customers,” Reavey said in the blog post.
Two medieval fortresses face each other across the Narva River separating Estonia from Russia on Europe’s eastern edge. Once a symbol of cooperation, the “Friendship Bridge” connecting the two snow-covered banks has been reinforced with rows of razor wire and “dragon’s teeth” anti-tank obstacles on the Estonian side. “The name is kind of ironic,” regional border chief Eerik Purgel said. Some fear the border town of more than 50,0000 people — a mixture of Estonians, Russians and people left stateless after the fall of the Soviet Union — could be Russian President Vladimir Putin’s next target. On the Estonian side of the bridge,
Jeremiah Kithinji had never touched a computer before he finished high school. A decade later, he is teaching robotics, and even took a team of rural Kenyans to the World Robotics Olympiad in Singapore. In a classroom in Laikipia County — a sparsely populated grasslands region of northern Kenya known for its rhinos and cheetahs — pupils are busy snapping together wheels, motors and sensors to assemble a robot. Guiding them is Kithinji, 27, who runs a string of robotics clubs in the area that have taken some of his pupils far beyond the rural landscapes outside. In November, he took a team
Civil society leaders and members of a left-wing coalition yesterday filed impeachment complaints against Philippine Vice President Sara Duterte, restarting a process sidelined by the Supreme Court last year. Both cases accuse Duterte of misusing public funds during her term as education secretary, while one revives allegations that she threatened to assassinate former ally Philippine President Ferdinand Marcos Jr. The filings come on the same day that a committee in the House of Representatives was to begin hearings into impeachment complaints against Marcos, accused of corruption tied to a spiraling scandal over bogus flood control projects. Under the constitution, an impeachment by the
SHOW OF SUPPORT: The move showed that aggression toward Greenland is a question for Europe and Canada, and the consequences are global, not just Danish, experts said Canada and France, which adamantly oppose US President Donald Trump’s wish to control Greenland, were to open consulates in the Danish autonomous territory’s capital yesterday, in a strong show of support for the local government. Since returning to the White House last year, Trump has repeatedly insisted that Washington needs to control the strategic, mineral-rich Arctic island for security reasons. Trump last month backed off his threats to seize Greenland after saying he had struck a “framework” deal with NATO chief Mark Rutte to ensure greater US influence. A US-Denmark-Greenland working group has been established to discuss ways to meet Washington’s security concerns