Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cloud
    • Cloud
    • Cybersecurity
    • Development
    • Networking

    Flame, Stuxnet Creators Collaborated, Researchers Say

    Written by

    Brian Prince
    Published June 11, 2012
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Researchers at Kaspersky Lab have found what they believe is a direct link between Flame and the Stuxnet malware that was discovered targeting uranium centrifuges at Iran’s nuclear facilities.

      According to Kaspersky, the main module in Flame contains code similar to what was found in an early iteration of Stuxnet. The discovery is significant, as many have questioned whether or not there was a connection between Stuxnet, Duqu€”also considered linked to Stuxnet€”and Flame.

      As it turns out, the first version of Stuxnet, referred to by Kaspersky as Stuxnet.A, appeared in June 2009 and differed greatly from later variants. The 2009 version, for example, did not use the MS10-046 LNK file vulnerability to propagate, but used a special trick with the autorun.inf file to infect USB drives. The 2009 version also only had one driver file, whereas the 2010 versions had two.

      The most significant change, however, involves something called €œresource 207,” a 520,192-bit DLL file that was dropped altogether in 2010 when its code was merged into other modules.

      “Resource 207€™s main functionality was to ensure Stuxnet propagation to removable USB drives via autorun.inf, as well as to exploit a then-unknown vulnerability in win32k.sys to escalate privileges in the system at [the] stage of infection from USB drive,” explained Alexander Gostev, head of the Global Research and Analysis team at Kaspersky.

      “Spreading via autorun.inf is another trick that the Stuxnet 2009 version and the current variants of Flame have in common,” Gostev noted.

      Inside Resource 207 is a portable executable (PE) file that is actually a Flame plug-in, or more precisely, a proto-Flame module that has “obviously a lot in common” with the current version of its main module, mssecmgr.ocx, Gostev added.

      This shared code, said Kaspersky Senior Virus Analyst Roel Schouwenberg, proves that there is a direct link between the pieces of malware and that there was early collaboration between their creators.

      “I think when it comes to source code, it€™s much less likely that you share your source code without knowing why. €¦you don’t just share that with anyone,” he said.

      Recently, a report in The New York Times featured several sources stating President Barack Obama ordered the use of cyber-attacks against Iran. The efforts, built on plans created during the administration of former President George W. Bush, were aimed at derailing Iran’s nuclear program.

      “The implications for war are interesting for two reasons: First, we must assume that multiple entities [possibly including sovereigns] are engaged in the same efforts; and second, technology is transferrable, as we’ve seen here,” noted Francis Cianfroca, chief executive officer at Bayshore Networks. “That means that as attacks become known and publicized, the techniques become easily exploitable by others. In a key sense, using cyber-weapons proliferates them. It’s quite plausible to think in terms of an arms race taking place in the subterranean cyber-world.”

      During the analysis of Duqu, which was first detected in 2011, researchers uncovered a number of similarities with Stuxnet and ultimately that they were created using the same attack platform, known as Tilded. Despite the newly discovered facts, however, researchers remain confident that Flame and Tilded are completely different platforms, and that the Stuxnet and Flame teams worked independently from 2010 on.

      “They each have different architectures with their own unique tricks that were used to infect systems and execute primary tasks,” according to Gostev. “The projects were indeed separate and independent from each other. However, the new findings that reveal how the teams shared source code of at least one module in the early stages of development prove that the groups cooperated at least once. What we have found is very strong evidence that Stuxnet/Duqu and Flame cyber-weapons are connected.”

      Brian Prince
      Brian Prince

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×