Business

Virus War: The Flame Malware Suspected to Be Waged by the US and Israel

Virus War: The Flame Malware Suspected to Be Waged by the US and Israel

In May 2012, researchers at the Russia-based antivirus firm Kaspersky Lab exposed one of the most sophisticated cyberespionage toolkits ever discovered: Flame, a sprawling malware platform targeting computers in Iran, Lebanon, and elsewhere in the Middle East.

The operation's scale was staggering. Kaspersky reported that the attackers had used an extensive list of fake identities to register at least 86 domains for their command-and-control infrastructure — a network that appeared to remain partially active even days after the operation was publicly exposed. The size of that infrastructure, the researchers said, exceeded anything they had seen before.

Everything about Flame suggested a state sponsor: its complexity, its modular design, its precise targeting of Iranian systems, and the resources required to build and maintain it. Security researchers and journalists quickly pointed to the United States and Israel as the likely authors — the same partnership widely believed to have built Stuxnet, the malware that had damaged Iranian nuclear centrifuges two years earlier. (Subsequent reporting would confirm that Flame was part of the same joint effort.)

The discovery landed as a milestone in the undeclared cyberwar over Iran's nuclear program — a war fought not with airstrikes but with code, fake identities, and command servers scattered across the internet.

This article summarizes contemporaneous reporting from June 2012, including Kaspersky Lab's published research.

cybersecurityFlameIranIsraelKaspersky LabUnited States

Related Stories