Skip to main content

Flame

Classification

Category:

Malware

Type:

Trojan

Aliases:

  • Flame
  • Trojan.Flame.A
  • Trojan.Flame.B
  • Trojan.Generic.KD.633944
  • Flamer
  • Skywiper

Summary

Flame is a sophisticated information-gathering program used in targeted cyber-attacks against organizations and nation states in the Middle East.

Removal

Technical Details

Flame is a massive, complex and sophisticated malware designed for information gathering and espionage. Initial reports have termed this malware an 'attack toolkit' or 'platform', as it includes capabilities similar to a trojan, a worm, and a botnet-controlled backdoor.

Though the identity of the attackers remains unknown, the objective of this malware appears to be information gathering focused on organizations, institutions or nation states in the Middle East. There is speculation that this form of espionage is most likely perpetrated by a rival nation state, though no strong confirmation currently exists.

Flame's technical complexity and its usage suggests a link with prior targeted malwares Stuxnet and Duqu, though there is no reported similarity in the source code of the various malwares.

Technical Details

Due to its massive size - approximately 20MB - and the complexity of its structure, analysis of the malware has been challenging and is still ongoing. The following details are based on information released in initial reports.

The malware itself is composed of multiple modules, each with specific roles. These components may be modified or removed, and new modules added, by the attackers. Among its reported capabilities are:

  • Replicates via removable media, and through local networks using known vulnerabilities
  • Capable of infecting Windows XP, Vista and 7 operating systems
  • Able capture environment sounds via the system's microphone
  • Able to capture screenshots when specific processes or windows are active
  • Able to forward saved information to a remote server
  • Multple command and control (C&C) servers and domains used

Initial reports indicate that multiple versions of Flame have been circulating in the wild for some time, without being detected by any major antivirus programs or other security software. At the time of writing, F-Secure has detections for known sample components.

More Information

More information, including technical analysis, is available from:

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.