Kaspersky Lab has released a new research related to the discovery of the nation-state sponsored Flamecyber-espionage campaign.
During the research, conducted by Kaspersky Lab in partnership with International Telecommunication Union's cybersecurity executing arm, IMPACT, CERT-Bund/BSI and Symantec, a number of Command and Control (C&C) servers used by Flame's creators were analyzed in detail.
The analysis revealed that traces of three yet undiscovered malicious programs were found, and it was discovered that the development of the Flame platform dates back to 2006.
Moreover, there were signs that the C&C platform was still under development. One communication scheme named “Red Protocol” is mentioned but not yet implemented.There is no sign that the Flame C&Cs were used to control other known malware such as Stuxnet or Gauss.
“It was problematic for us to estimate the amount of data stolen by Flame, even after the analysis of its Command and Control servers. Flame’s creators are good at covering their tracks. But one mistake of the attackers helped us to discover more data that one server was intended to keep. Based on this, we can see that more than five gigabytes of data was uploaded to this particular server a week, from more than 5,000 infected machines. This is certainly an example of cyber espionage conducted on a massive scale,” stated Alexander Gostev, Chief Security Expert, Kaspersky Lab.




