Researchers have discovered a new version of the infamous Trojan Flame

The malware Flame was considered dead after it was uncovered by specialists from Kaspersky Lab in 2012. The mentioned virus represents a complex set of tools intended for conducting espionage on a national scale. After the public disclosure, the operators of Flame attempted to cover their tracks by deleting the virus's presence from infected computers, most of which were located in the Middle East and North Africa.

Now, specialists from Chronicle Security, a part of Alphabet, have managed to find traces of a modified version of Flame. It is believed that the Trojan was actively used by attackers from 2014 to 2016. Researchers state that the attackers did not destroy the malware but rather revamped it, making it more complex and less detectable by security tools.

Researchers have discovered a new version of the infamous Trojan Flame

Additionally, specialists found evidence of the use of the sophisticated malware Stuxnet, which was used in 2007 to sabotage Iran's nuclear program. Experts believe that Stuxnet and Flame share similar characteristics, which may indicate a common origin for these Trojan programs. It is thought that Flame was developed in Israel and the USA, and the malware itself was utilized for espionage activities. Notably, when discovered, the Flame virus was the first modular platform, allowing components to be replaceable based on the specifics of the attacked system.

Currently, researchers have obtained new tools that help search for traces of past attacks, shedding light on some of them. As a result, files that were compiled in early 2014 were discovered, approximately a year and a half after Flame's disclosure. It is noted that at that time, no antivirus programs identified these files as malicious. The modular Trojan program has numerous features that enable espionage activities. For example, it can turn on the microphone on the infected device to record conversations happening nearby.

Unfortunately, researchers have not been able to uncover the full potential of Flame 2.0, the updated version of the dangerous Trojan program. Its protection was based on encryption, which prevented specialists from examining the components in detail. Therefore, the question of Flame 2.0's capabilities and methods of distribution remains open.




Source: 3dnews.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster