Pages

Showing posts with label flame. Show all posts
Showing posts with label flame. Show all posts

Thursday, July 26, 2012

'AC/DC virus' hits Iran nuke plants

from torontosun.com: An Internet security company says it received a report nuclear plants in Iran were hit by a virus that makes their computers play music by the rock band AC/DC.

In a blog post earlier this week, F-Secure Labs, which monitors spyware, phishing and other cyber threats, said a scientist working at the Atomic Energy Organization of Iran (AEOI) sent “a series of e-mails” saying computer systems at the Natanz and Fordo nuclear facilities had been infected by a computer worm. The sender said hackers shut down their automation network and Siemens hardware.

Chief research officer at F-Secure Corporation in Finland - Mikko Hypponen, confirmed the nuclear scientist was sending and receiving e-mails from within the AEOI but could not verify any of the other details.

Iran’s nuclear facilities have recently been infected by viruses called Flame and Stuxnet, which Hypponen told the International Business Times were part of a joint U.S.-Israel cyber espionage operation.

Monday, June 11, 2012

US Ignites Cyber Warfare Through Stuxnet, Flame Malware

US Ignites Cyber Warfare Through Stuxnet, Flame Malwarefrom brasschecktv.com: "Do as I say, not as I do," is the very definition of authoritarianism. In instigating cyber attacks while simultaneously declaring state sponsored cyber attacks to be "acts of war" it is more than just hypocritical, it could lead to a real military war. It also demonstrates that the administration is not truly interested in "negotiations", that's just a public relations front, while behind the scenes it's all about moving forward with the war. Abby Martin discusses the 'Stuxnet' computer virus and cyber warfare policy with Trevor Timm of the Electronic Frontier Foundation...

Related Updates:
Part of 'Flame' code found in Iranian computers same as Stuxnet*

Researchers Connect Flame to U.S.-Israel Stuxnet Attack*

Wednesday, May 30, 2012

Iran Computers Hit By New Malware: Meet Flame!

Iran Computers Hit By New Malware:  Meet Flame!
Wired Threat Level introduces newest computer malware: "Flame". "Kaspersky [Lab] discovered the malware about two weeks ago after the United Nations’ International Telecommunications Union asked the Lab to look into reports in April that computers belonging to the Iranian Oil Ministry and the Iranian National Oil Company had been hit with malware that was stealing and deleting information from the systems," reveals article.  The inevitable tendency is to compare to Stuxnet and DuQu previous malware that likewise attacked Iran computer networks.

Threat Level compares similarities and differences of Stuxnet and DuQu to Flame:
"Stuxnet and DuQu were made of compact and efficient code that was pared down to its essentials. Flame is 20 megabytes in size, compared to Stuxnet’s 500 kilobytes, and contains a lot of components that are not used by the code by default, but appear to be there to provide the attackers with options to turn on post-installation. 'It was obvious DuQu was from the same source as Stuxnet. But no matter how much we looked for similarities [in Flame], there are zero similarities,' [ chief security expert at Kaspersky Lab, Alexander] Gostev said. “Everything is completely different, with the exception of two specific things.”
"One of these is an interesting export function in both Stuxnet and Flame, which may turn out to link the two pieces of malware upon further analysis, Gostev said. The export function allows the malware to be executed on the system. Also, like Stuxnet, Flame has the ability to spread by infecting USB sticks using the autorun and .lnk vulnerabilities that Stuxnet used. It also uses the same print spooler vulnerability that Stuxnet used to spread to computers on a local network. This suggests that the authors of Flame may have had access to the same menu of exploits that the creators of Stuxnet used."
Threat Level implies current computer worm, Flame is another large project that requires state backing: "a massive, highly sophisticated piece of malware has been newly found infecting systems in Iran and elsewhere and is believed to be part of a well-coordinated, ongoing, state-run cyberespionage operation."