mystery virus sought to \steal designs from iran\
Last Updated : GMT 09:03:51
Almaghrib Today, almaghrib today
Almaghrib Today, almaghrib today
Last Updated : GMT 09:03:51
Almaghrib Today, almaghrib today

Microsoft warns of infection risk by Flame

Mystery virus sought to 'steal designs from Iran'

Almaghrib Today, almaghrib today

Almaghrib Today, almaghrib today Mystery virus sought to 'steal designs from Iran'

A screengrab of the Flame computer virus
Moscow - Agencies

A screengrab of the Flame computer virus A mystery computer virus discovered last month and deployed in a massive cyberattack chiefly against Iran sought to steal designs and PDF files from its victims, a Russian firm said.Kaspersky Lab, one of the world's biggest producers of anti-virus software, announced last month the discovery of the Flame virus, which it described as the biggest and most sophisticated malware ever seen.
In the latest update on Kaspersky's analysis of the virus, released late Monday, the firm's chief security expert, Alexander Gostev, said the malware's creators had focussed on file formats such as PDF and AutoCAD, a software for computer design and drawing.
"The attackers seem to have a high interest in AutoCAD drawings," Gostev said in a statement.
The malware also "goes through PDF and text files and other documents and makes short text summaries," he added.
"It also hunts for e-mails and many different kinds of other 'interesting' (high-value) files that are specified in the malware configuration."
He confirmed that Iran was by far the biggest target with a count of 185 infections, followed by 95 in Israel and the Palestinian Territories, 32 in Sudan and 29 in Syria.
The discovery of Flame immediately sparked speculation that it had been created by US and Israeli security services to steal information about Iran's controversial nuclear drive.
Intriguingly, Kaspersky said that hours after the existence of the virus was first announced on May 28, "The Flame command-and-control infrastructure, which had been operating for years, went dark."
It gave no further information over the possible perpetrators of the mystery attack, though it identified about 80 domains that appear to belong to the Flame infrastructure, in locations from Hong Kong to Switzerland.
Kaspersky said it had used a procedure known as sinkholing -- which allows Internet security experts to gain control of a malicious server -- to analyse the operation.
During the sinkholing it found that on three computers in Lebanon, Iraq and Iran the Flame versions changed, suggesting Flame upgraded itself in the process.
The New York Times reported last week that president Barack Obama has accelerated cyberattacks on Iran's nuclear programme in an operation codenamed "Olympic Games" that uses a malicious code developed with Israel.
Meanwhile, Microsoft Corp warned that a bug in Windows allowed PCs across the Middle East to become infected with Flame and released a software fix to fight the espionage tool that surfaced last week.
Security experts said they were both surprised and impressed by the approach that the attackers had used, which was to disguise Flame as a legitimate programme built by Microsoft.
Experts described the method as “elegant” and they believed it had likely been used to deliver other cyber weapons yet to be identified.
“It would be logical to assume that they would have used it somewhere else at the same time,” Mikko Hypponen, chief research officer for security software maker F-Secure, said.
If other types of cyber weapons were indeed delivered to victim PCs using the same approach as Flame, then they will likely be exposed very quickly now that Microsoft has identified the problem, said Adam Meyers, director of intelligence for security firm CrowdStrike.
Cyber weapons that bear the fake Microsoft code will either stop working or lose some of their camouflage, said Ryan Smith, chief research scientist with security firm Accuvant.
A spokeswoman for Microsoft declined to comment on whether other viruses had exploited the same flaw in Windows or if the company’s security team was looking for similar bugs in the operating system.
News of the Flame virus, which surfaced a week ago, generated headlines around the world as researchers said that technical evidence suggests it was built on behalf of the same nation or nations that commissioned the Stuxnet worm that attacked Iran’s nuclear programme in 2010. Researchers are still gathering information about the virus.
 

almaghribtoday
almaghribtoday

Name *

E-mail *

Comment Title*

Comment *

: Characters Left

Mandatory *

Terms of use

Publishing Terms: Not to offend the author, or to persons or sanctities or attacking religions or divine self. And stay away from sectarian and racial incitement and insults.

I agree with the Terms of Use

Security Code*

mystery virus sought to \steal designs from iran\ mystery virus sought to \steal designs from iran\

 



Name *

E-mail *

Comment Title*

Comment *

: Characters Left

Mandatory *

Terms of use

Publishing Terms: Not to offend the author, or to persons or sanctities or attacking religions or divine self. And stay away from sectarian and racial incitement and insults.

I agree with the Terms of Use

Security Code*

mystery virus sought to \steal designs from iran\ mystery virus sought to \steal designs from iran\

 



Almaghrib Today, almaghrib today Skincare PR Performance Full Year 2017

GMT 09:22 2018 Monday ,22 January

Skincare PR Performance Full Year 2017
Almaghrib Today, almaghrib today New hunt for flight MH370 gets under way

GMT 11:03 2018 Wednesday ,24 January

New hunt for flight MH370 gets under way
Almaghrib Today, almaghrib today Modern colorful bedroom renovation

GMT 10:57 2017 Thursday ,21 December

Modern colorful bedroom renovation
Almaghrib Today, almaghrib today Puigdemont candidate for Catalan president

GMT 13:56 2018 Tuesday ,23 January

Puigdemont candidate for Catalan president
Almaghrib Today, almaghrib today Turkey detains dozens more

GMT 10:47 2018 Wednesday ,24 January

Turkey detains dozens more

GMT 08:28 2012 Monday ,12 November

IBQ revamps private bank business to maintain edge

GMT 22:13 2012 Tuesday ,10 April

IBQ chief: Too many banks in Qatar

GMT 23:14 2012 Thursday ,05 April

UN rights chief calls for Trayvon Martin probe

GMT 13:07 2011 Saturday ,17 December

Chelsea target Ross Barkley

GMT 03:27 2014 Tuesday ,22 April

China stocks open mixed Tuesday

GMT 22:15 2017 Tuesday ,08 August

Saving lives gets tougher for Med's charity boats

GMT 12:02 2013 Monday ,25 February

Lebanon’s al-Rahi urges politicians to resign

GMT 16:25 2013 Tuesday ,27 August

Britain not seeking to topple Assad: Deputy PM

GMT 18:41 2011 Friday ,19 August

French winger Huget handed 3-month doping ban

GMT 12:49 2013 Wednesday ,30 January

I am not the star of my movies

GMT 15:03 2013 Friday ,02 August

Guerlain unveils autumn collection

GMT 11:33 2016 Wednesday ,06 January

China 'firmly opposes' North Korean nuclear test

GMT 13:09 2015 Tuesday ,25 August

Bahrain condemns suicide attack in Beheira
Almaghrib Today, almaghrib today
 
 Almaghrib Today Facebook,almaghrib today facebook  Almaghrib Today Twitter,almaghrib today twitter Almaghrib Today Rss,almaghrib today rss  Almaghrib Today Youtube,almaghrib today youtube  Almaghrib Today Youtube,almaghrib today youtube

Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2021 ©

Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2021 ©

.almaghribtoday .almaghribtoday .almaghribtoday .almaghribtoday
almaghribtoday almaghribtoday almaghribtoday
almaghribtoday
بناية النخيل - رأس النبع _ خلف السفارة الفرنسية _بيروت - لبنان
almaghribtoday, Almaghribtoday, Almaghribtoday