Technology, Discovery & Innovation NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
This ad will display for the next 20 seconds. Click for more information, or
Home Computing Digital Life Discovery Space More Topics...
Advertisement
Free Gartner Report:
Drive innovation & collaboration
with the "Everyone's IT" approach.

View the research report
Viruses & Malware
Average Rating:
Rate this article:  
Flame Coders Left Digital Fingerprints Behind

Flame Coders Left Digital Fingerprints Behind
By Jennifer LeClaire

Share
Share on Facebook Share on Twitter Share on Linkedin Share on Google Plus

Unlike traditional cyber criminals who implement eye-candy Web interfaces which the average user can recognize as a botnet control panel, Kaspersky said, the developers of the Flame Command-and-Control servers made the Flame interface generic and unpretentious. "We believe this was deliberately done to deceive hosting company sys-admins."
 



Security researchers often play the role of Sherlock, but they don't always have such telling clues to sleuth. The hackers behind the Flame malware, which has been used in nation-state espionage attacks, have left a trail of hints that may help authorities tag the culprits.

The clues also point to evidence that the attack was under way and much broader than once thought.

Let's back up a minute. Known as W32.Flamer, Symantec describes this malware as a sophisticated cyber espionage tool. Flamer made headlines after cyber attacks on Middle Eastern countries earlier in 2012. Both Symantec and Kaspersky are now releasing new analyses of the command-and-control (C&C) servers used in those attacks.

"The servers were set up on March 25, 2012, and May 18, 2012, respectively. On both occasions, within only a few hours of the server being setup, the first interaction with a computer compromised with Flamer was recorded," Symantec wrote in its blog. "The servers would go on to control at least a few hundred compromised computers over the next few weeks of their existence."

No Exclusivity

Symantec goes on to reveal that the servers contained the same control framework, but were used for distinct purposes. Symantec estimates the server that was set up in March, for example, collected almost 6 GB of data from compromised computers in just over a week. By contrast, the security firm reports, the server that was set up in May 2012 received just 75 MB of data and was used solely to distribute one command module to the compromised computers.

"Command-and-control happens through a Web application called Newsforyou. The application processes the W32.Flamer client interactions and provides a simple control panel. The control panel allows the attackers to upload packages of code to deliver to compromised computers, and to download packages containing stolen client data," Symantec said.

"This application does not appear to be exclusively used by Flamer. It contains functionality that allows it to communicate with computers compromised with multiple malware identifiers using different protocols."

Script-Kiddies?

For its part, Kaspersky reveals that a European company with data centers in another European Union country own one of the C&C servers it analyzed. Kaspersky managed to get a server image that was an OpenVZ file-system container.

"Our first impression was that the control panel appeared to be implemented by script-kiddies. It looked like a very early alpha version of a botnet C&C control panel," Kaspersky wrote in its blog. "However, revisiting this picture one more time made everything clear -- the attackers deliberately chose this interface."

Unlike traditional cyber-criminals who implement eye-candy Web interfaces which the average user can easily recognize as a botnet control panel, the security firm said, the developers of the Flame C&C made it very generic and unpretentious.

"The C&C developers didn't use professional terms such as bot, botnet, infection, malware-command or anything related in their control panel. Instead they used common words like data, upload, download, client, news, blog, ads, backup etc.," Kaspersky said. "We believe this was deliberately done to deceive hosting company sys-admins who might run unexpected checks."
 

Tell Us What You Think
Comment:

Name:



Get Powerful App Acceleration with Cisco. In a world where time is money, you need to accelerate the speed at which data moves through your data center. Cisco UCS Invicta delivers powerful, easy-to-manage application acceleration for data-intensive workloads. So you can make decisions faster and outpace the competition. Learn More.


 Viruses & Malware
1.   9 Norton Security Products Are Now 1
2.   Data Stolen from U.S. Health Network
3.   Beware Facebook Color Scam
4.   Kaspersky Looks Inside 'Epic' Attack
5.   BadUSB Turns Thumb Drives Evil


advertisement
Android 'Fake ID' Puts Millions at Risk
Users: stick to apps from Google Play.
Average Rating:
Data Stolen from U.S. Health Network
Chinese hackers targeted hospital firm.
Average Rating:
9 Norton Security Products Are Now 1
Symantec takes software-as-service tack.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Researchers Find Malicious Android Apps Can Hack Gmail
A new study shows that a weakness in the Android mobile operating system can be used to steal sensitive, personal info from unwitting users. Gmail proved to be the easiest app to attack; Amazon, the hardest.
 
UPS Stores in 24 States Hit by Data Breach
Big Brown has been breached. UPS said that about 105,000 customer transactions at 51 of its UPS Store locations in 24 states could have been compromised between January and August.
 
Cost of Target Data Breach: $148 Million Plus Loss of Trust
The now infamous Target data breach is still costing the company -- and its shareholders -- plenty. In fact, the retailing giant forecast the December 2013 incident cost shareholders $148 million.
 

Enterprise Hardware Spotlight
Acer's New Desktop Box Rides the Chrome OS Wave
Filling out its Chrome OS line, Acer is following the introduction of a larger Chromebook line earlier this month with a new tiny $180 desktop Chromebox and also a smaller Chromebook.
 
Feds OK $2.3 Billion IBM-Lenovo x86 Server Deal
IBM and Lenovo are celebrating U.S. approval of their x86-based server deal, having cleared some major security hurdles. The deal makes Lenovo a major player for enterprise data centers.
 
Three New Lenovo PCs Aimed at Business Users
With businesses wanting computing solutions that do more for less money, Lenovo has unveiled three new desktop PCs that it says offer solid computing at a budget-minded price.
 

Mobile Technology Spotlight
Screen Shortage Briefly Puts Brakes on iPhone 6
RAM? Check. Antenna switch? Check. Screen? Oops. Parts suppliers for Apple have found themselves facing a shortage of screens for the new iPhone 6 as next month's release date for the new smartphone looms.
 
Bounty Offered to Coders for Oculus Rift Bugs
Coders who find bugs in software for the Oculus Rift VR immersive headset could receive a reward of at least $500 under Facebook's White Hat bounty program. Facebook acquired Oculus in March.
 
Google Glass Adds Voice Access to Phone Contacts
The latest update to Google Glass will let users access their top 20 phone contacts with voice commands alone. A user can then choose a phone call, Google hangouts, e-mail or text messaging.
 

Navigation
Sci-Tech Today
Home/Top News | Computing | Digital Life | Discovery | Space | Innovation | Health | Science News
Environment
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.