Skip to main content

Kaspersky: Cyberweapons Flame and Stuxnet share code

Flame malware / cyberweapon
Image used with permission by copyright holder

When word of the sophisticated Flame cyberweapon first came out a couple weeks ago, Russian security firm Kaspersky indicated that despite some superficial similarities, there was no indication Flame had much of anything in common with Stuxnet, a software weapon that specifically targeted Iran’s uranium-enrichment efforts and then escaped into the wild. Now, Kaspersky says it was wrong: The firm claims to have uncovered shared code that indicate the creators of Flame and Stuxnet at least worked together — and may even be the same people.

Flame has attracted considerable attention in security circles for its sophisticated architecture the enables attackers to install modules tailored to their interest in a particular systems. Various modules appear to perform “normal” malware tasks like scanning through users’ files and logging keystrokes; Flame modules have also been found that appear to take screenshots, turn on audio microphones to record audio, and even poll nearby Bluetooth devices for contacts and other information.

The evidence? Back when Stuxnet was roaming free, Kaspersky’s automated systems picked up on something that looked like a Stuxnet variant. When Kaspersky’s staff initially looked at it, they couldn’t really understand why their systems thought it was Stuxnet, assumed it was an error, and reclassified it under the name “Tocy.a.” When Flame, appeared, however, Kaspersky went back to look for things that might link Flame to Stuxnet — and, lo and behold, there the Tocy.a variant that didn’t make any sense. In light of Flame, Kaspsersky says Tocy.a actually makes more sense: it’s an early version of a plug-in module for Flame that implements what (at the time) was a zero-day privilege escalation exploit in Windows. Tocy.a wandered into Kaspersky’s systems all the way back in October 2010, and contains code that can be traced to 2009.

“We think it’s actually possible to talk about a ‘Flame’ platform, and that this particular module was created based on its source code,” wrote Kaspersky’s Alexander Gostev.

If Kaspersky’s analysis is correct, it would indicate the “Flame platform” was already up and running by the time the original Stuxnet was created and set loose back in early-to-mid 2009. The approximate dating is possible because the proto-Flame code only appears in the first version of the Stuxnet worm: It vanished from two subsequent versions of Stuxnet that appeared in 2010.

Kaspersky infers that the highly-modular Flame platform proceeded on a different development path from Stuxnet, meaning there were at least two development teams involved. But the present of that early version of a Flame module seems to indicate the Stuxnet developers had access to source code for a true zero-day Windows exploit that was (at that point) unknown to the broader security community. That means the two teams were pretty tight, at least at one point.

The New York Times has reported that Stuxnet was created as a cyberweapon by the United States and Israel in an effort to hample Iran’s uranium enrichment activities. Since the discovery of Flame and its subsequent analysis by computer security firms, Flame’s creators have apparently sent a “suicide” command to some Flame-infected systems in an effort to remove traces of the software.

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Best home internet deals for September 2024: AT&T, Spectrum, Optimum and more
how to optimize wifi network for work from home wrt1900acs router position location direction improve signal

for better or for worse, much of our modern world relies on the internet to access the very basic things in life, whether it's your banking information or your entertainment content; having a good internet connectino is important. Luckily, there are quite a lot of options out there these days, and some of them go beyond just providing you with internet, and can often include options for unlimited phone plans and TV channels. That's probably great if you enjoy streaming movies, live sports, and TV shows since they tend to eat up a lot of data, so going for a bundled deal can certainly save you quite a bit of extra money in the process.

So whether you want to cut the cord, improve your online gaming experience, or just upgrade your sluggish internet service to a faster one, this up-to-date roundup of the best high-speed internet deals and bundles is the place to start. Thankfully, the ubiquity of high-speed internet means you can get the bandwidth you need at cheaper prices than ever before. As fiber-optic networks roll out across the country, gigabit internet is also more accessible. You should also check out these wireless router deals to save even more money on equipment rental fees.
Best home internet deals

Read more
Best 2-in-1 laptop deals: Turn your laptop into a tablet for $349
Lenovo Yoga 9i 14 Gen 7 laptop sits on a small desk folded like a tent.

If you find that your traditional laptop isn't quite doing it for you in terms of workflow, then you might want to consider taking some of what the best tablets and the best laptops have and combining them together in the form of 2-in-1 laptops. These can offer a ton of versatility to your workflow, such as being able to use them in handheld mode for drawing or presenting, as well as the fact that most, if not all, are touch-enabled, so you don't even have to use a mouse if you don't want to.
There are, of course, a ton of great choices out there, but some of the best 2-in-1 laptops can get quite expensive, especially when you're buying them from some of the best laptop brands out there. That's why we've gone out and looked for our favorite 2-in-1 laptop deals to help save you some effort. Be sure to check all our picks below.

Asus Chromebook Plus 2-in-1 -- $349, was $499

Read more
Best Apple Studio Display deals: Save $299 on 5K monitors
Apple Mac Studio and Studio Display.

If you're working on things that require a high-end monitor with excellent resolution and image fidelity, then the Apple Studio Display is what you're looking for, especially if you're in the Apple ecosystem and using things like the Apple MacBook Pro and the Apple MacBook Air. As a 5k monitor, it blows a lot of other monitors out of the water, although it does come with a deep price tag, so if you're the sort of creative pro that's looking to up their game, you'll likely want to grab yourself a good monitor deal. Lukcily, you can get some good discounts on the Apple Studio Display, depending on which model your looking for, and if you're thinking of pairing this with a new Apple computer, check out some of these Apple deals as well.
Apple Studio Display — $1,300, was $1,599

The Apple Studio Display is one of the more premium monitors on the market. It’s not to be confused with the Apple Pro Display XDR, which is Apple’s professional, high end monitor. And while the Apple Studio Display and Pro Display XDR have some similarities, the Studio Display comes in at a much lower price tag. It has a 27-inch screen that comes with 5K resolution and 600 nits of brightness, as well as support for one billion colors and the P3 wide color gamut. It also has a six-speaker sound system with Spatial Audio, which makes it a great place to sit down and watch movie.

Read more