Flame is the most sophisticated and powerful malicious program that created to target Iranian uranium enrichment process. It creates a backdoor to access a computer on a network and spread via shared files and USB drives. Flame steals data from the affected computer and monitors every activity of the user on the computer. It was 1st found in Iranian oil network. Flame is considered as another dangerous cyber weapon and used as cyber espionage by attackers.
Flame initially spread through a spear phishing email and website. Moreover, it can be spread via infected USB drive and infected PC in LAN. The worm is a 20MB file that contains encryption algorithms, multiple libraries, SQLite3 databases, 20 plugins – provide the platform for attackers and some code written in LUA language which vulnerable to Microsoft Windows computer.
When flame infects the computer, all data files will be collected. Then the machine's settings would be remotely modified. The worm switches on the PCs microphone and record voice conversation. Furthermore, it records message conversation, scan keyboard inputs, Wi-Fi, network, storage devices, and system process and gets location by saved images. In addition, the flame has a component which can scan traffic on infected machines LAN that provides administrative access to the attacker for other machines in the LAN.
The flame worm is 20 times greater and its complexity and functionality surpass the Stuxnet. Besides, it cannot self – propagate, but it can be allowed by some hidden controllers.
"we are all now connected by the Internet like neurons in a giant brain" - Stephen Hawking
Comments
Post a Comment